teamviewer_setup.exe

TODO:

File Verified

This is the InstallMetrix bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application teamviewer_setup.exe by File Verified has been detected as adware by 18 anti-malware scanners. The program is a setup application that uses the InstallMetrix Software installer. The file has been seen being downloaded from us1.download.teamviewer.com.
Publisher:
TODO: <Company name>  (signed by File Verified)

Product:
TODO: <Product name>

Description:
TeamViewer_Setup

Version:
1.0.0.1

MD5:
09901925d9de258e73594dc8cbf2fa9a

SHA-1:
21fdc2a93eece9d1df99790d3d80efbede9e6488

SHA-256:
769ac011b52a691f59d7f3dcd183d56101a88126e05d9ae57603e8c392530196

Scanner detections:
18 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 4:20:58 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.InstallMetrix
7.1.1

Avira AntiVirus
Adware/InstallMet.hc
7.11.184.252

avast!
Win32:Rootkit-gen [Rtk]
2014.9-141124

AVG
Generic
2015.0.3292

Clam AntiVirus
Win.Adware.Installmonster-8
0.98/21411

Dr.Web
Trojan.Domaiq.7
9.0.1.0328

ESET NOD32
Win32/Adware.InstallMetrix (variant)
8.10687

F-Prot
W32/A-215008ab
v6.4.7.1.166

IKARUS anti.virus
PUA.InstallMetrix
t3scan.1.8.3.0

K7 AntiVirus
Adware
13.185.13943

Kaspersky
not-a-virus:AdWare.Win32.InstallMonster
14.0.0.2897

NANO AntiVirus
Riskware.Win32.InstallMonster.dhazif
0.28.6.62995

Norman
InstallMetrix.E
11.20141112

Panda Antivirus
Trj/Genetic.gen
14.11.24.12

Reason Heuristics
PUP.Installer.FileVerified.Q
14.11.12.22

Vba32 AntiVirus
AdWare.InstallMonster
3.12.26.3

VIPRE Antivirus
Threat.4150696
34232

Zillya! Antivirus
Adware.InstallMonster.Win32.42
2.0.0.1977

File size:
1013.1 KB (1,037,440 bytes)

Product version:
1.0.0.1

Copyright:
Copyright (C) 2014

Original file name:
Installer.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
InstallMetrix Software

Language:
English (United States)

Common path:
C:\users\{user}\downloads\teamviewer_setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
10/9/2014 8:00:00 PM

Valid to:
10/10/2015 7:59:59 PM

Subject:
CN=File Verified, OU=File Verified, O=File Verified, STREET="660 4th Street, Suite 427", L=San Francisco, S=California, PostalCode=94107, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
3218B54F8331C296189D5EA9E74030ED

File PE Metadata
Compilation timestamp:
11/7/2014 3:26:55 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:2k3YNwjfcu0+MOKtUZkTn2NX7D+T5ZPfY8TX:3YNcfJ0zUZk+H+13z

Entry address:
0x681A

Entry point:
E8, 50, 1B, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 08, 0D, 41, 00, 89, 0D, 04, 0D, 41, 00, 89, 15, 00, 0D, 41, 00, 89, 1D, FC, 0C, 41, 00, 89, 35, F8, 0C, 41, 00, 89, 3D, F4, 0C, 41, 00, 66, 8C, 15, 20, 0D, 41, 00, 66, 8C, 0D, 14, 0D, 41, 00, 66, 8C, 1D, F0, 0C, 41, 00, 66, 8C, 05, EC, 0C, 41, 00, 66, 8C, 25, E8, 0C, 41, 00, 66, 8C, 2D, E4, 0C, 41, 00, 9C, 8F, 05, 18, 0D, 41, 00, 8B, 45, 00, A3, 0C, 0D, 41, 00, 8B, 45, 04, A3, 10, 0D, 41, 00, 8D, 45, 08, A3, 1C, 0D, 41...
 
[+]

Entropy:
7.8259  (probably packed)

Code size:
39.5 KB (40,448 bytes)

The file teamviewer_setup.exe has been seen being distributed by the following URL.

Remove teamviewer_setup.exe - Powered by Reason Core Security