avpreinstaller.exe

TVzavr LLC

The executable avpreinstaller.exe has been detected as malware by 9 anti-virus scanners. This is a setup and installation application and has been known to bundle potentially unwanted software.
Publisher:
TVzavr LLC  (signed and verified)

MD5:
14e1b5e9ba36052b88dfe76ccc24c6cd

SHA-1:
94d7d9303636fbd534becc08763a43ddb7b78f99

SHA-256:
6bbe2f0b28e9a5cf503ca8a1831ee2d0837de5a2201d89c6aa8ef79f694fa780

Scanner detections:
9 / 68

Status:
Malware

Analysis date:
4/18/2024 9:58:12 PM UTC  (today)

Scan engine
Detection
Engine version

Bitdefender
Trojan.Generic.8594263
1.0.20.190

F-Secure
Trojan.Generic.8594263
11.2016-07-02_1

G Data
Trojan.Generic.8594263
16.2.22

Kaspersky
HEUR:Trojan-Downloader.Win32.Generic
14.0.0.696

MicroWorld eScan
Trojan.Generic.8594263
17.0.0.114

NANO AntiVirus
Trojan.Win32.Revealer.bcvdht
0.22.6.49175

nProtect
Trojan.Generic.8594263
13.01.17.01

Vba32 AntiVirus
Trojan-Downloader.Genome.deex
3.12.18.4

ViRobot
Trojan.Win32.A.Downloader.53728.A[UPX]
2011.4.7.4223

File size:
52.5 KB (53,728 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\avpreinstaller.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
2/9/2012 3:00:00 AM

Valid to:
3/11/2013 2:59:59 AM

Subject:
CN=TVzavr LLC, O=TVzavr LLC, L=Moscow, S=Moscow, C=RU

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
6D018D174CAE27BD907B605166D0252F

File PE Metadata
Compilation timestamp:
7/19/2012 6:23:23 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
768:GWKmnqpJYYs5cHOUeoFtEHP8XVUKyM9uc8jcCQ7cfw9tiVpRNHvjuZnXtFh+wIIt:ZnGXGoF20XVU57c8K7mYUpDAnXtFh7t

Entry address:
0x22C20

Entry point:
60, BE, 00, 80, 41, 00, 8D, BE, 00, 90, FE, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, EF, 75, 09, 8B, 1E, 83, EE, FC, 11, DB, 73, E4, 31, C9, 83, E8, 03, 72, 0D, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 74, 89, C5, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 75, 20, 41, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
44 KB (45,056 bytes)

Remove avpreinstaller.exe - Powered by Reason Core Security