mtv_cai_1001.exe

M直播安装程序

北京天瑞地安网络科技有限公司

The application mtv_cai_1001.exe by 北京天瑞地安网络科技有限公司 has been detected as a potentially unwanted program by 15 anti-malware scanners.
Publisher:

Product:
M直播安装程序

Version:
1.3.0.2

MD5:
a7e2d6e5378f3f9e1d8303bbebc3c5e8

SHA-1:
7678b19177ecc7d165ccda132819b84bef5427b9

SHA-256:
f45517ed183e11725be66585c88addb0c76d35af1c59f4fde6c62e48155ee132

Scanner detections:
15 / 68

Status:
Potentially unwanted

Analysis date:
8/8/2025 12:57:37 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.RansomKD.3386378
193

AegisLab AV Signature
Troj.Samca.Kbqw!c
2.1.4+

Avira AntiVirus
TR/Samca.kbqw
8.3.3.4

avast!
Win32:Adware-gen [Adw]
2014.9-160725

AVG
Generic7
2017.0.2671

Dr.Web
Trojan.Inject2.24950
9.0.1.0207

ESET NOD32
Win32/Adware.Agent.NQL (variant)
10.13830

G Data
Win32.Application.Agent.A7W0X0
16.7.25

IKARUS anti.virus
Virus.Win32.BHO
t3scan.2.1.6.0

K7 AntiVirus
Adware
13.235.20289

Kaspersky
not-a-virus:RiskTool.Win32.Kuping
14.0.0.-148

McAfee
Artemis!A7E2D6E5378F
5600.6327

Sophos
Generic PUA HG (PUA)
4.98

Trend Micro
TROJ_GEN.R03EC0OGH16
10.465.25

VIPRE Antivirus
Trojan.Win32.Generic
50972

File size:
3.1 MB (3,262,704 bytes)

Product version:
1.3.0.2

Original file name:
Install.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\mtv_cai_1001.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/7/2015 7:00:00 AM

Valid to:
5/7/2016 6:59:59 AM

Subject:
CN=北京天瑞地安网络科技有限公司, O=北京天瑞地安网络科技有限公司, L=北京市, S=北京市, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6CAC2D28C3F0828B2EF49B40AA2B1287

File PE Metadata
Compilation timestamp:
7/6/2016 3:37:47 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:9Kd3vpqNIAGf+5X/41lTM3+PBg82vY0PTauwW3PxW:+RqNbCa4XTt5T2vjh3PxW

Entry address:
0x392A7

Entry point:
E8, B3, 64, 00, 00, E9, 79, FE, FF, FF, 3B, 0D, C0, 1A, 4A, 00, 75, 02, F3, C3, E9, 35, 65, 00, 00, 8B, FF, 55, 8B, EC, 8B, 45, 14, 56, 57, 33, FF, 3B, C7, 74, 47, 39, 7D, 08, 75, 1B, E8, 2B, 0F, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, 6F, 04, 00, 00, 83, C4, 14, 8B, C6, EB, 29, 39, 7D, 10, 74, E0, 39, 45, 0C, 73, 0E, E8, 06, 0F, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, D7, 50, FF, 75, 10, FF, 75, 08, E8, EC, 65, 00, 00, 83, C4, 0C, 33, C0, 5F, 5E, 5D, C3, 8B, C1, 83, 60, 04, 00, 83, 60, 08, 00...
 
[+]

Entropy:
7.7867  (probably packed)

Code size:
514.5 KB (526,848 bytes)

Remove mtv_cai_1001.exe - Powered by Reason Core Security