tdvbv.exe

NHN USA Inc.

The executable tdvbv.exe has been detected as malware by 38 anti-virus scanners. It runs as a windows Service named “Microsoft Framework COM+ Support”.
Publisher:
NHN USA Inc.  (signed and verified)

MD5:
88c3239505c12707c6dddaf2fb13b48f

SHA-1:
4cfc2a4bf15f1f2af7ec49739724d409a89491e3

SHA-256:
2465fafbe30255f643008140d5e4ce53e52f6a19a1799c29fa49a5586f4446aa

Scanner detections:
38 / 68

Status:
Malware

Analysis date:
11/27/2024 9:00:33 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Generic.ServStart.C76CE8FF
371

Agnitum Outpost
Rootkit.Lapka
7.1.1

AhnLab V3 Security
Malware/Win32.Generic
2015.12.10

Avira AntiVirus
TR/Staser.apzjs
8.3.2.4

Arcabit
Generic.ServStart.C76CE8FF
1.0.0.629

avast!
Win32:GenMalicious-BKJ [Trj]
2014.9-160129

AVG
Generic_r
2017.0.2849

Baidu Antivirus
Trojan.Win32.Rootkit
4.0.3.16129

Bitdefender
Generic.ServStart.C76CE8FF
1.0.20.145

Clam AntiVirus
Win.Trojan.Microfake-3
0.98/21511

Comodo Security
UnclassifiedMalware
23732

Dr.Web
Trojan.PWS.Gamania.44384
9.0.1.029

Emsisoft Anti-Malware
Generic.ServStart.C76CE8FF
8.16.01.29.07

ESET NOD32
Win32/ServStart (variant)
10.12695

Fortinet FortiGate
W32/Lapka.AN!tr.rkit
1/29/2016

F-Secure
Generic.ServStart.C76CE8FF
11.2016-29-01_6

G Data
Generic.ServStart.C76CE8FF
16.1.25

IKARUS anti.virus
Trojan.Win32.Patcher
t3scan.1.9.5.0

K7 AntiVirus
Trojan-Downloader
13.212.18054

Kaspersky
Rootkit.Win32.Lapka
14.0.0.741

Malwarebytes
Backdoor.Bot
v2016.01.29.07

McAfee
BackDoor-FBOD!88C3239505C1
5600.6505

Microsoft Security Essentials
DDoS:Win32/Nitol.A
1.1.12300.0

MicroWorld eScan
Generic.ServStart.C76CE8FF
17.0.0.87

NANO AntiVirus
Trojan.Win32.Gamania.duxjys
1.0.10.5081

nProtect
Generic.ServStart.C76CE8FF
15.12.09.01

Panda Antivirus
Trj/Genetic.gen
16.01.29.07

Qihoo 360 Security
Win32/Trojan.e6a
1.0.0.1077

Quick Heal
DDoS.Nitol.r2 (Not a Virus)
1.16.14.00

Rising Antivirus
PE:Backdoor.Overie!1.64BD [F]
23.00.65.16127

Sophos
Mal/Generic-S
4.98

Total Defense
Win32/Nitol.PMdeWaB
37.1.62.1

Trend Micro House Call
TROJ_NITOL.SMN1
7.2.29

Trend Micro
TROJ_NITOL.SMN1
10.465.29

Vba32 AntiVirus
Rootkit.Lapka
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Nitol.b
45714

ViRobot
Trojan.Win32.R.Agent.142016[h]
2014.3.20.0

Zillya! Antivirus
Rootkit.Lapka.Win32.1493
2.0.0.2556

File size:
138.7 KB (142,016 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\temp\tdvbv.exe

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
11/2/2009 6:00:00 PM

Valid to:
10/28/2011 6:59:59 PM

Subject:
CN=NHN USA Inc., O=NHN USA Inc., L=Irvine, S=California, C=US

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
2B5A383157EFC7CD2617EF32F0A7ACB9

File PE Metadata
Compilation timestamp:
6/2/2015 6:39:37 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:ms1v/yX1insPOo2t2HYJCnci3XXHAiK6zpJGMDDDDDDDDDDDjDDDDDDDDDDDDDDO:ms1nyXvAUJms6

Entry address:
0x6A48

Entry point:
55, 8B, EC, 6A, FF, 68, 90, 23, 40, 00, 68, C0, 69, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, F8, 10, 40, 00, 59, 83, 0D, FC, 95, 40, 00, FF, 83, 0D, 00, 96, 40, 00, FF, FF, 15, FC, 10, 40, 00, 8B, 0D, F8, 95, 40, 00, 89, 08, FF, 15, 00, 11, 40, 00, 8B, 0D, F4, 95, 40, 00, 89, 08, A1, 04, 11, 40, 00, 8B, 00, A3, 04, 96, 40, 00, E8, 10, 01, 00, 00, 39, 1D, F0, 1B, 40, 00, 75, 0C, 68, C4, 6B, 40, 00, FF, 15, 08, 11...
 
[+]

Entropy:
5.0372

Developed / compiled with:
Microsoft Visual C++ v6.0

Service
Display name:
Microsoft Framework COM+ Support

Service name:
Microsoft CLR

Description:
Microsoft Integration with SOAP

Type:
Win32OwnProcess, InteractiveProcess


Remove tdvbv.exe - Powered by Reason Core Security