TeViiRC.exe

TeVii Remote Control

JacTek Multimedia Co.,Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘TeViiRC’.
Publisher:
TeVii Technology Ltd.  (signed by JacTek Multimedia Co.,Ltd.)

Product:
TeVii Remote Control

Version:
1.0.0

MD5:
c3e30956d831609a34c5ee0307edf17c

SHA-1:
19e4834118247bd8232479d4a12aed2b67d51266

SHA-256:
c796cec4c233e6562159d88e7730b311bab147aa9d4f2d4cf00b90ae11f975ef

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/16/2024 4:16:26 AM UTC  (today)

File size:
320.6 KB (328,328 bytes)

Product version:
1.0.0

Copyright:
Copyright (C) 2010 TeVii Technology Ltd.

Original file name:
TeViiRC.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\windows\teviirc.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/29/2010 3:15:18 AM

Valid to:
10/29/2011 3:15:18 AM

Subject:
CN="JacTek Multimedia Co.,Ltd.", O="JacTek Multimedia Co.,Ltd.", C=TW

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012BF5A1F51E

File PE Metadata
Compilation timestamp:
4/21/2010 10:04:33 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:IhaJfFqyJTrUlj5d0P/xbeyaM73I4j3E509omaRcw5+JNWBi5:TTr05q773Ic3E5j7cC+Ki5

Entry address:
0x227BD

Entry point:
E8, 2E, 86, 00, 00, E9, 78, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, 56, 8B, 44, 24, 14, 0B, C0, 75, 28, 8B, 4C, 24, 10, 8B, 44, 24, 0C, 33, D2, F7, F1, 8B, D8, 8B, 44, 24, 08, F7, F1, 8B, F0, 8B, C3, F7, 64, 24, 10, 8B, C8, 8B, C6, F7, 64, 24, 10, 03, D1, EB, 47, 8B, C8, 8B, 5C, 24, 10, 8B, 54, 24, 0C, 8B, 44, 24, 08, D1, E9, D1, DB, D1, EA, D1, D8, 0B, C9, 75, F4, F7, F3, 8B, F0, F7, 64, 24, 14, 8B, C8, 8B, 44, 24, 10, F7, E6, 03, D1, 72, 0E, 3B, 54, 24, 0C, 77, 08, 72, 0F, 3B, 44, 24, 08, 76, 09...
 
[+]

Code size:
208 KB (212,992 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
TeViiRC

Command:
C:\windows\teviirc.exe


Scan TeViiRC.exe - Powered by Reason Core Security