teamviewer.exe

The application teamviewer.exe has been detected as a potentially unwanted program by 6 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from doc-04-ak-docs.googleusercontent.com.
MD5:
1da148b6e0421ad3fe1d72ff32d541a3

SHA-1:
27c29e28fd3227951b10024b04bedd0a8657e3b2

SHA-256:
65832680a6c72c22285620a9aa6e3e9a67dc0bc0316160fd32280e5b551171a8

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
12/25/2024 1:21:03 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Agent-XW [Trj]
160414-2

Emsisoft Anti-Malware
Gen:Trojan.Heur.MR.wqZ@amZJf!nc
11.5.0.6191

ESET NOD32
Win32/Spy.PerfKey.U.Gen trojan
8.0.319.0

F-Prot
W32/Banker.ALWM
4.6.5.141

Kaspersky
not-a-virus:Monitor.Win32.Perflogger
15.0.0.562

Microsoft Security Essentials
Threat.Undefined
1.225.1578.0

File size:
360.7 KB (369,336 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\My documents\downloads\teamviewer.exe

File PE Metadata
Compilation timestamp:
3/3/2001 1:25:22 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
6144:OY94NI2v7zySMU+9+qgPCxbEZGbA7YYhIXVTDjvcHKYEJE94TS/3uAXtd5cadoOZ:l9OIWYTgPgBXqIXVD4K49eSRf5JuOGls

Entry address:
0x1000

Entry point:
E9, 5F, 10, 00, 00, 00, 00, 00, 00, 90, 90, 90, 6A, 00, 68, 58, 10, 40, 00, 6A, 00, 68, 12, 71, 40, 00, FF, 35, 5C, 78, 40, 00, E8, 8B, 5E, 00, 00, 83, 3D, 64, 78, 40, 00, 00, 75, 1B, 83, 3D, 70, 78, 40, 00, 00, 75, 12, B9, 03, 00, 00, 00, 8B, 15, 40, 70, 40, 00, 33, C0, E8, 84, 06, 00, 00, 80, 3D, 3C, 70, 40, 00, 00, 74, 05, E8, 7D, 0E, 00, 00, C3, 55, 8B, EC, 50, B8, 02, 00, 00, 00, 81, C4, 04, F0, FF, FF, 50, 48, 75, F6, 81, C4, 04, F2, FF, FF, 8B, 45, FC, 53, 56, 57, 8B, 7D, 10, 8B, 5D, 0C, 8B, 75, 08...
 
[+]

Entropy:
7.9099

Packer / compiler:
WinRAR, 0x32-bit SFX Module

Code size:
24 KB (24,576 bytes)

The file teamviewer.exe has been seen being distributed by the following URL.

Remove teamviewer.exe - Powered by Reason Core Security