fituner.exe

Cyberservices B.V.

Part of the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application fituner.exe by Cyberservices B.V has been detected as adware by 10 anti-malware scanners. The file has been seen being downloaded from www.freeinternettuner.com.
Publisher:
Cyberservices B.V.  (signed and verified)

MD5:
0931c75465a915bfab73673884b6621e

SHA-1:
7cac38eaa41a52aeff91291a3b05a9f71f1f476f

SHA-256:
694cde21c491dedf5ff1d17a0724bab977508c77db0d8755cc88e5cc64232349

Scanner detections:
10 / 68

Status:
Adware

Analysis date:
4/25/2024 1:13:35 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
BundleApp
2015.0.3508

Baidu Antivirus
Trojan.Win32.DownloadGuide
4.0.3.14410

Dr.Web
Adware.Downware.2522
9.0.1.0100

ESET NOD32
Win32/DownloadGuide (variant)
8.9658

G Data
Win32.Application.DownloadGuide
14.4.24

Malwarebytes
PUP.Optional.Breitschopp
v2014.04.10.02

McAfee
Artemis!1E890461B0CE
5600.7007

Reason Heuristics
PUP.CyberservicesBV.H
14.4.10.14

Trend Micro House Call
TROJ_GEN.F47V0402
7.2.100

VIPRE Antivirus
DownloadGuide
28184

File size:
450 KB (460,824 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\fituner.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/9/2014 7:00:00 PM

Valid to:
2/10/2016 6:59:59 PM

Subject:
CN=Cyberservices B.V., O=Cyberservices B.V., STREET=Keizersgracht 62-64 NL, L=Amsterdam, S=Nordholland, PostalCode=1015CS, C=NL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
797CAC4561E8B8B21910CD01E0002669

File PE Metadata
Compilation timestamp:
3/28/2014 5:11:58 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:5SJKsfw2HqmALCoRZlflvMak16CtOle+syF6GH8VPflPrGGu8V5oGl+T4reQR:5mQmcXtlvQFInuVX1TuGEELR

Entry address:
0x1A3C7

Entry point:
E8, AD, 48, 00, 00, E9, 89, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 44, 24, 08, 8B, 4C, 24, 10, 0B, C8, 8B, 4C, 24, 0C, 75, 09, 8B, 44, 24, 04, F7, E1, C2, 10, 00, 53, F7, E1, 8B, D8, 8B, 44, 24, 08, F7, 64, 24, 14, 03, D8, 8B, 44, 24, 08, F7, E1, 03, D3, 5B, C2, 10, 00, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, CC, 7D, 42, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40...
 
[+]

Entropy:
6.9855

Code size:
147.5 KB (151,040 bytes)

The file fituner.exe has been seen being distributed by the following URL.

Remove fituner.exe - Powered by Reason Core Security