TDSSKiller.exe

TDSSKiller

Kaspersky Lab

This is a setup program which is used to install the application. The file has been seen being downloaded from files.downloadnow.com and multiple other hosts.
Publisher:
Kaspersky Lab ZAO  (signed by Kaspersky Lab)

Product:
TDSSKiller

Description:
TDSS rootkit removing tool

Version:
3.1.0.7

MD5:
2e199070abb82d0a945bba032710e1ec

SHA-1:
15d25b673b220941d3d008cde555cad4c0565f08

SHA-256:
6171869d841cf451aea022d6d5d2befa4c0790b5bc312404cdffcf2a77779dc1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 12:22:57 AM UTC  (today)

File size:
4.2 MB (4,398,264 bytes)

Product version:
3.1.0.7

Copyright:
© 1997-2015 Kaspersky Lab ZAO.

Trademarks:
Kaspersky™ Anti-Virus ® is registered trademark of Kaspersky Lab ZAO.

Original file name:
TDSSKiller.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\kasperskytdsskillerportable\app\tdsskiller\tdsskiller.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
10/27/2014 1:00:00 AM

Valid to:
11/3/2017 1:00:00 PM

Subject:
CN=Kaspersky Lab, O=Kaspersky Lab, L=Moscow, S=Moscow City, C=RU, PostalCode=125212, STREET=39A/3 Leningradskoe shosse, SERIALNUMBER=1027739867473, OID.1.3.6.1.4.1.311.60.2.1.2=Moscow, OID.1.3.6.1.4.1.311.60.2.1.3=RU, OID.2.5.4.15=Private Organization

Issuer:
CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0D0C681CE3699DB3F3234F70A5CDD362

File PE Metadata
Compilation timestamp:
11/29/2015 8:37:29 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:UEGuknnhOibaTMmfyEUHDq4+aG6LVLdzc5ts8knQ8c:3LknnhqfxUjq4+wLdqE8xV

Entry address:
0x893334

Entry point:
50, 9C, 60, E8, 0C, 01, 00, 00, 01, 00, 00, 00, 00, 00, 40, 00, 00, 00, 00, 00, 34, 33, 89, 00, 48, 22, 42, 00, A0, 32, 89, 00, 91, 00, 00, 00, 98, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 80, CB, 88, 00, 98, 21, 89, 00, 6C, 24, 89, 00, 0C, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 50, 45, 00, 48, 22, 42, 00, 00, 7E, 43, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Code size:
4.2 MB (4,423,680 bytes)

The file TDSSKiller.exe has been seen being distributed by the following 6 URLs.