teamviewer_setup_en.exe

TeamViewer

TeamViewer

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is installed with multiple programs including TeamViewer 10 and TeamViewer 9. The file has been seen being downloaded from webportal.bel.co.in and multiple other hosts.
Publisher:
TeamViewer GmbH  (signed by TeamViewer)

Product:
TeamViewer

Version:
9.0.24951.0

MD5:
62c568a1a882501e1764c6726e8a3c2e

SHA-1:
1e9a96696cfcccbb24e8cd61666da7f5ca54d73b

SHA-256:
8cc19966cb280518c475f9acc74b5dfbebc8ea9b424a194966834bb4c20329b1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/29/2024 6:03:43 AM UTC  (today)

File size:
5.8 MB (6,035,264 bytes)

Product version:
9.0.24951.0

Copyright:
TeamViewer GmbH

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\teamviewer_setup_en.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/7/2011 8:00:00 PM

Valid to:
8/7/2014 7:59:59 PM

Subject:
CN=TeamViewer, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=TeamViewer, L=Goeppingen, S=Baden Wuerttemberg, C=DE

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3D27AFBEA5996F13E5B5624421F16295

File PE Metadata
Compilation timestamp:
2/24/2012 2:19:54 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:NBoHbkqv9IxM0WhQgw570H9/lP8IrN1ChOBYznuz/GB+BynBi8HW:NBjqv9I8DIg99P88wyDwPM8HW

Entry address:
0x3883

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, 92, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 36, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, 92, 40, 00, FF, 15, 84, 81, 40, 00, 68, 4C, 92, 40, 00, 68, C0, AD, 46, 00, E8, 18, 27, 00, 00, FF, 15, B0, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 06, 27, 00, 00...
 
[+]

Entropy:
7.9932

Packer / compiler:
Nullsoft install system v2.x

Code size:
27.5 KB (28,160 bytes)

The file teamviewer_setup_en.exe has been discovered within the following programs.

TeamViewer 10  by TeamViewer GmbH
5% remove it
TeamViewer 9  by TeamViewer GmbH
Publisher's description - “Remote control any computer or Mac over the internet within seconds or use TeamViewer for online meetings. Open multiple remote sessions in tabs, just like in your browser.”
www.TeamViewer.com
6% remove it
 
Powered by Should I Remove It?

The file teamviewer_setup_en.exe has been seen being distributed by the following 26 URLs.

http://webportal.bel.co.in/SAPHelp/.../TeamViewer_Setup_en_9.04.exe

https://doc-00-ac-docs.googleusercontent.com/docs/securesc/klla8lfgqltpmtltmmf94d360ia4j9ha/mgoht4u52fhvfjloeb7aft4ps6h428ga/1474466400000/.../15851138759600646536/0B7TMH9g_tp3qM0VKRTFsSmdGRFk?e=download