teamviewer_setup-afu.exe

TeamViewer GmbH

This is a setup program which is used to install the application. This is installed with TeamViewer 5 (MSI Wrapper). The file has been seen being downloaded from mishakoosha.com and multiple other hosts.
Publisher:
TeamViewer GmbH  (signed and verified)

MD5:
6c33241db6331a8d8743d61c66a6cf6e

SHA-1:
ecea2bbb8217f7a9d651b791e98496f0bc0e1655

SHA-256:
b2b402220d9b19b86f4ad2295ab5effe8c37c0ed1a8b37d6c624c8249a73b4ce

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/21/2024 8:46:53 PM UTC  (today)

File size:
3 MB (3,099,848 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\teamviewer_setup-afu.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/16/2008 1:00:00 AM

Valid to:
2/23/2011 12:59:59 AM

Subject:
CN=TeamViewer GmbH, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=TeamViewer GmbH, S=Baden Wuerttemberg, C=DE

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
25C902D026E31244C125996771C9DC01

File PE Metadata
Compilation timestamp:
6/6/2009 11:41:48 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:Pg6XnLp7Kf+Q2N05nU+PqimBsAXKqaIxeJJsUL/FdHWl+xfXunyBvPJ/V987H6ST:PgAck0tU/CAXNdeXnJ2ofXXBpt07T

Entry address:
0x35240

Entry point:
60, BE, 00, 10, 43, 00, 8D, BE, 00, 00, FD, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, EF, 75, 09, 8B, 1E, 83, EE, FC, 11, DB, 73, E4, 31, C9, 83, E8, 03, 72, 0D, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 74, 89, C5, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 75, 20, 41, 01, DB, 75...
 
[+]

Packer / compiler:
UPX 2.90LZMA]

Code size:
20 KB (20,480 bytes)

The file teamviewer_setup-afu.exe has been discovered within the following program.

TeamViewer 5 (MSI Wrapper)  by TeamViewer GmbH
TeamViewer MSI is an alternative installation package for the full version or TeamViewer Host. It's used for deploying TeamViewer via Group Policy (GPO) in an Active Directory domain.
www.teamviewer.com
10% remove it
 
Powered by Should I Remove It?

The file teamviewer_setup-afu.exe has been seen being distributed by the following 8 URLs.

http://mishakoosha.com/.../TeamViewer_Setup.exe

https://www.neatoscan.com/TeamViewer_Setup.exe

http://www.lmip.com.br/.../TeamViewer_Setup.exe