teamviewer_setup.exe

TeamViewer

TeamViewer

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is installed with TeamViewer 7. The file has been seen being downloaded from remoteflashit.com and multiple other hosts.
Publisher:
TeamViewer GmbH  (signed by TeamViewer)

Product:
TeamViewer

Version:
7.0.17271.0

MD5:
82203859bad19a1b651f9e2e451f39f1

SHA-1:
660f057276f75638d30c820839b02837041c2393

SHA-256:
018f3c348b80aae1fdf1728f6fef23d1f122eb8cf66cae25f9d20abe578289b7

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 2:23:19 AM UTC  (today)

File size:
4.7 MB (4,959,400 bytes)

Product version:
7.0.17271.0

Copyright:
TeamViewer GmbH

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\teamviewer_setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/8/2011 1:00:00 AM

Valid to:
8/8/2014 12:59:59 AM

Subject:
CN=TeamViewer, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=TeamViewer, L=Goeppingen, S=Baden Wuerttemberg, C=DE

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3D27AFBEA5996F13E5B5624421F16295

File PE Metadata
Compilation timestamp:
2/24/2012 7:19:54 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:Wbv9RLOZN3NCK3cT+/npzUhR82LquhfyMv9YyNnRoc/a/pPDnCXALbv:WbQ3PpIRzmudyMvNdIpPDn2Cv

Entry address:
0x3883

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, 92, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 36, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, 92, 40, 00, FF, 15, 84, 81, 40, 00, 68, 4C, 92, 40, 00, 68, C0, AD, 46, 00, E8, 18, 27, 00, 00, FF, 15, B0, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 06, 27, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
27.5 KB (28,160 bytes)

The file teamviewer_setup.exe has been discovered within the following program.

TeamViewer 7  by TeamViewer GmbH
Publisher's description - “TeamViewer is a simple and fast solution for remote control, desktop sharing and file transfer that works behind any firewall and NAT proxy. To connect to another computer just run TeamViewer on both machines without the need of an installation procedure.”
www.teamviewer.com/en/download/windows.aspx
7% remove it
 
Powered by Should I Remove It?

The file teamviewer_setup.exe has been seen being distributed by the following 43 URLs.

http://remoteflashit.com/TeamViewer_Setup.exe

http://www.toucharger.com/.../b7695871.dl

http://c236.x8top.net/2107tmp/cf/soft/2013/7/.../teamviewer_7017271.exe

http://f51.x8top.net/2107tmp/cf/soft/2013/7/.../teamviewer_7017271.exe

http://f51.y8top.net/2107tmp/cf/soft/2013/7/.../teamviewer_7017271.exe

http://www.toucharger.com/download/media/.../teamviewer-7_1_22656.exe

http://c236.y8top.net/2107tmp/cf/soft/2013/7/.../teamviewer_7017271.exe

http://downloadeu4.teamviewer.com/download/.../TeamViewer_Setup.exe

http://download.teamviewer.com/download/.../TeamViewer_Setup.exe

http://f30.x8top.net/2107tmp/cf/soft/2013/7/.../teamviewer_7017271.exe

https://doc-10-bk-docs.googleusercontent.com/docs/securesc/2lmvkrddq9gj889ves1h921a7nfm4cnr/nisue5fpdmf1a2r28v4sivgnb6orinuf/1422316800000/10963874666145463863/.../0B9lvmDpqLPK1VkhkV3ZuckxBaTA?h=04751224724558272769&e=download

Latest 30 of 43 download URLs