getnowupdater.exe

GetNowUpdater

SIEN Internet Products Ltd

This is the SIEN AppScion Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application getnowupdater.exe by SIEN Internet Products has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the SIEN SuperInstall installer. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘GetNowUpdater’.
Publisher:
Live_Soft_Action S.R.L.  (signed by SIEN Internet Products Ltd)

Product:
GetNowUpdater

Version:
1.0.1.9

MD5:
f87609f820bc79d88f396a5da64534f0

SHA-1:
db2b2c5ebbb458bb449d79f3459429ddf7a886d4

SHA-256:
dce2fb7bf0b26dc7e2b89274e26e36c6a7656299270eba2bcc15ac29e9be1fbf

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
11/27/2024 1:29:56 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Sien (M)
17.1.28.7

File size:
4.3 MB (4,543,088 bytes)

Product version:
1.0.1.9

Copyright:
Copyright (C) 2013

Original file name:
GetNowUpdater

File type:
Executable application (Win32 EXE)

Bundler/Installer:
SIEN SuperInstall

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\getnowupdater\update.0\bin\getnowupdater.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
2/2/2015 10:13:19 AM

Valid to:
2/3/2016 10:13:19 AM

Subject:
CN=SIEN Internet Products Ltd, O=SIEN Internet Products Ltd, L=London, C=GB

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121B83795C783CB891BECAAAEEF4B5E1F5B

File PE Metadata
Compilation timestamp:
4/27/2015 11:18:17 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x193B21

Entry point:
E8, 72, 50, 01, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 33, C9, 3B, 04, CD, 68, 74, 80, 00, 74, 13, 41, 83, F9, 2D, 72, F1, 8D, 48, ED, 83, F9, 11, 77, 0E, 6A, 0D, 58, 5D, C3, 8B, 04, CD, 6C, 74, 80, 00, 5D, C3, 05, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8, 1B, C0, 23, C1, 83, C0, 08, 5D, C3, E8, 97, 62, 00, 00, 85, C0, 75, 06, B8, D0, 75, 80, 00, C3, 83, C0, 08, C3, E8, 84, 62, 00, 00, 85, C0, 75, 06, B8, D4, 75, 80, 00, C3, 83, C0, 0C, C3, 8B, FF, 55, 8B, EC, 56, E8, E2, FF, FF, FF, 8B, 4D, 08...
 
[+]

Code size:
2.9 MB (3,065,856 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
GetNowUpdater

Command:
"C:\users\{user}\appdata\roaming\getnowupdater\update.0\bin\getnowupdater.exe" \silent_startup


Remove getnowupdater.exe - Powered by Reason Core Security