tgvie9kd.exe

Runner Utility

BERSHNET LLC

The file tgvie9kd.exe by BERSHNET has been detected as adware by 23 anti-malware scanners. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. It is also typically executed from the user's temporary directory.
Publisher:
Dummy, Ltd.  (signed by BERSHNET LLC)

Product:
Runner Utility

Version:
1.0.0.187

MD5:
e6beb1bdf9a05630a3c19a407f0705e9

SHA-1:
81d857442bde8a9ead261f588f16e4411fdb8b28

SHA-256:
5446907181309cdf31af9b7a189ceda7f8a08af81096a47c392db6e042690f97

Scanner detections:
23 / 68

Status:
Adware

Analysis date:
4/24/2024 5:17:27 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Mikey.8247
6324531

AhnLab V3 Security
PUP/Win32.LoadMoney
2015.03.29

Avira AntiVirus
ADWARE/Adware.Gen7
3.6.1.96

AVG
Generic
2016.0.3156

Bitdefender
Gen:Variant.Adware.Mikey.8247
1.0.20.435

Comodo Security
Application.Win32.LoadMoney.IARS
21575

Dr.Web
Trojan.Amonetize
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Mikey.8247
9.0.0.4799

ESET NOD32
Win32/Amonetize.DW potentially unwanted application
7.0.302.0

F-Prot
W32/S-40484255
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Mikey
5.13.68

G Data
Gen:Variant.Adware.Mikey.8247
15.3.25

K7 AntiVirus
Unwanted-Program
13.202.15414

Kaspersky
not-a-virus:Downloader.Win32.Agent
15.0.0.543

Malwarebytes
PUP.Optional.Amonetize
v2015.03.28.10

MicroWorld eScan
Gen:Variant.Adware.Mikey.8247
16.0.0.261

Panda Antivirus
Trj/Genetic.gen
15.03.28.10

Reason Heuristics
PUP.BERSHNET
15.3.28.22

VIPRE Antivirus
Threat.4785227
38552

File size:
1.5 MB (1,524,752 bytes)

Product version:
1.0.0.187

Copyright:
Copyright (C) 2013

Original file name:
runner.exe

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\tgvie9kd.exe.part

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/5/2015 4:00:00 PM

Valid to:
2/6/2016 3:59:59 PM

Subject:
CN=BERSHNET LLC, O=BERSHNET LLC, STREET="st. 600-richya b.66, of.10", L=Vinnitsya, S=Vinnitskaya, PostalCode=21027, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E2D6C6F8DDF832E09DCF766B299AD2A9

File PE Metadata
Compilation timestamp:
3/1/2015 6:03:07 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
24576:Ap6J34mK3NOZT+NTc8ouB13HtQkx55SDnCRltJEb8CSfBzfc2M+110L0gb2Zxv4P:SYrK3N4ITZT73HekJSTCjRx5zf71oCZW

Entry address:
0x3D20CA

Entry point:
E8, 26, 6E, FF, FF, E8, 28, 40, F1, FF, E8, 9B, 3B, F1, FF, E9, 5B, D2, F1, FF, 41, C0, DA, E1, 73, 95, 07, 15, B4, 2C, 55, 02, 90, 80, 4E, 72, F8, D8, A6, AA, AF, 12, F8, 81, 75, 60, CC, 5C, 75, 8F, 07, 3D, F0, 82, 42, 10, 01, 9D, D0, B2, 5B, E8, EF, 8A, 52, E2, AF, F1, 46, BA, 00, 20, B1, 36, 4B, 96, FF, 92, E7, 60, 39, 67, E6, 85, 2B, 61, B4, 73, 5E, F3, B3, 4D, 75, 55, 17, BF, F6, 5C, 4D, 2B, 3F, 00, CE, 93, 05, C0, C0, A1, 9F, 6B, 5C, A4, 5A, C6, 1B, E5, C4, F3, CE, AB, 87, 12, F2, 36, D1, CE, 3A, 88...
 
[+]

Entropy:
7.9941  (probably packed)

Code size:
187.5 KB (192,000 bytes)

Remove tgvie9kd.exe - Powered by Reason Core Security