imsetup.exe

Setup

SIEN S.A.

This is the SIEN AppScion Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application imsetup.exe by SIEN S.A has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the SIEN SuperInstall installer. This is the uninstaller utility registered in the Windows Control Panel for the program Iminent by Iminent. This file is typically installed with the program Iminent by IMinent which is a potentially unwanted software program.
Publisher:
SIEN  (signed by SIEN S.A.)

Product:
Setup

Description:
Iminent

Version:
8.46.4.1

MD5:
2c2dee4620ea727c47deec65c4b06516

SHA-1:
e16893ec0ab084a8db5f87a5c9a29b0b2846d7f9

SHA-256:
b68c3c8d42a470d1f74e77398becb5a54da8daf667ce4d5d62e6f488a1fe4bae

Scanner detections:
2 / 68

Status:
Potentially unwanted

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
11/26/2024 9:05:32 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.SIENSA.H
14.3.1.8

VIPRE Antivirus
Iminent
24416

File size:
2.1 MB (2,166,112 bytes)

Product version:
8.46.4.1

Copyright:
(c)SIEN S.A. All rights reserved.

Original file name:
IminentSetup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
SIEN SuperInstall

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\imsetup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/21/2012 9:00:00 PM

Valid to:
8/22/2014 8:59:59 PM

Subject:
CN=SIEN S.A., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=SIEN S.A., L=Paris, S=France, C=FR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
514EA00D30C8C244C3E818890BF73967

File PE Metadata
Compilation timestamp:
11/14/2013 7:00:51 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:mq4dwE3DhzaYTlQ+58LRmQfP9VYs6L7cgoSZUWGh1nRsPjsHDZ2nUrJqyaCvMg:4Th5TlQAVQfP9VYs6L7cgoSZateP4on3

Entry address:
0x136055

Entry point:
E8, 61, 8F, 00, 00, E9, 89, FE, FF, FF, 3B, 0D, B0, 00, 5C, 00, 75, 02, F3, C3, E9, E8, 8F, 00, 00, 8B, FF, 55, 8B, EC, 51, 53, 56, 8B, 35, 78, 92, 56, 00, 57, FF, 35, A8, 9E, 5C, 00, FF, D6, FF, 35, A4, 9E, 5C, 00, 8B, D8, 89, 5D, FC, FF, D6, 8B, F0, 3B, F3, 0F, 82, 81, 00, 00, 00, 8B, FE, 2B, FB, 8D, 47, 04, 83, F8, 04, 72, 75, 53, E8, 00, 5D, 00, 00, 8B, D8, 8D, 47, 04, 59, 3B, D8, 73, 48, B8, 00, 08, 00, 00, 3B, D8, 73, 02, 8B, C3, 03, C3, 3B, C3, 72, 0F, 50, FF, 75, FC, E8, 1B, 91, 00, 00, 59, 59, 85...
 
[+]

Code size:
1.4 MB (1,474,048 bytes)

Program Uninstaller
Program name:
Iminent

Display publisher:
Iminent

Display version:
7.5.3.1

Uninstall string:
"C:\Program Files\Iminent\inst\Bootstrapper\IminentUninstall.exe" /uninstall


The file imsetup.exe has been discovered within the following programs.

Iminent  by IMinent
Iminent toolbar is a browser extension for Internet Explorer and Firefox which is used to emoticons while using Facebook and web-based email products. During installation the Iminent toolbar changes your browser's homepage to seach.iminent.
www.iminent.com
68% remove it
 
Powered by Should I Remove It?

The file imsetup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to i0-h0-s1122.p4-dfw.cdngp.net  (174.35.21.101:80)

TCP (HTTP):
Connects to 94.31.29.55.IPYX-077437-ZYO.above.net  (94.31.29.55:80)

Remove imsetup.exe - Powered by Reason Core Security