iminentsetup.exe

Iminent

This is the installer and setup program from the Iminent branded Yontoo adware web browser extension. This adware injects various forms of advertisements in the user's web browser based on the HTML content and URLs viewed. Ad include banners, in-line context text links, coupons, and search. The program will install an auto-updating Windows service that will update the software with additional features. The application iminentsetup.exe by Iminent has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the SIEN SuperInstall installer.
Publisher:
Iminent  (signed and verified)

MD5:
15fca3ad393fe08e83250d44e692efe5

SHA-1:
164be8da1d8d54ca3564a20ebe7223cd915f6bd4

SHA-256:
a1de836d4e474914958aa840c47cc7a1c29089b8add1e5302eb2b72579e48dfe

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/23/2024 4:03:01 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Sien (M)
17.1.30.1

File size:
838.5 KB (858,672 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
SIEN SuperInstall

Common path:
C:\users\{user}\downloads\iminentsetup.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
1/31/2012 10:55:45 AM

Valid to:
3/2/2014 10:55:45 AM

Subject:
CN=Iminent, O=Iminent, L=Paris, S=France, C=FR

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11214EA925C07E01E1C06B597DD4B36FAA8B

File PE Metadata
Compilation timestamp:
1/19/2014 10:25:28 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

Entry address:
0x4CCEC

Entry point:
83, C6, 01, C1, E9, 02, 83, C7, 01, 83, F9, 08, 72, 88, F3, A5, FF, 24, 95, 98, D2, 44, 00, 8D, 49, 00, 8F, D2, 44, 00, 7C, D2, 44, 00, 74, D2, 44, 00, 6C, D2, 44, 00, 64, D2, 44, 00, 5C, D2, 44, 00, 54, D2, 44, 00, 4C, D2, 44, 00, 8B, 44, 8E, E4, 89, 44, 8F, E4, 8B, 44, 8E, E8, 89, 44, 8F, E8, 8B, 44, 8E, EC, 89, 44, 8F, EC, 8B, 44, 8E, F0, 89, 44, 8F, F0, 8B, 44, 8E, F4, 89, 44, 8F, F4, 8B, 44, 8E, F8, 89, 44, 8F, F8, 8B, 44, 8E, FC, 89, 44, 8F, FC, 8D, 04, 8D, 00, 00, 00, 00, 03, F0, 03, F8, FF, 24, 95...
 
[+]

Code size:
444.5 KB (455,168 bytes)

Remove iminentsetup.exe - Powered by Reason Core Security