tsantimalware.exe

Cyberw Media Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Threat Support Anti-Malware’.
Publisher:
Anti-Malware  (signed by Cyberw Media Inc.)

Product:
Anti-Malware

Version:
1.0.0.0

MD5:
8925e8d92323adc8af443c905b1bb593

SHA-1:
5dc067a56e8c36b81f5343b21504bd9121017478

SHA-256:
a6a768e595dee2ca961bd279b55a2cf1dd43e2ff2d61da61e7031f76c5da5507

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
7/16/2025 1:50:28 PM UTC  (today)

File size:
2.5 MB (2,573,904 bytes)

Product version:
1.0.0.0

Original file name:
AntiMalware.exe

File type:
Executable application (Win64 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\threat support\threat support anti-malware\tsantimalware.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
9/16/2016 8:00:00 PM

Valid to:
3/20/2019 8:00:00 AM

Subject:
CN=Cyberw Media Inc., O=Cyberw Media Inc., L=Longueuil, S=Quebec, C=CA, PostalCode=J4H 2G5, STREET=300 Rue Joliette, STREET=Le De Serigny 309, SERIALNUMBER=1169960508, OID.1.3.6.1.4.1.311.60.2.1.2=Quebec, OID.1.3.6.1.4.1.311.60.2.1.3=CA, OID.2.5.4.15=Private Organization

Issuer:
CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0FD9A25A1086DA42A2239266B87BED7A

File PE Metadata
Compilation timestamp:
10/10/2016 8:52:33 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
48.0

.NET CLR dependent:
Yes

Entry point:
4D, 5A, 90, 00, 03, 00, 00, 00, 04, 00, 00, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 80, 00, 00, 00, 0E, 1F, BA, 0E, 00, B4, 09, CD, 21, B8, 01, 4C, CD, 21, 54, 68, 69, 73, 20, 70, 72, 6F, 67, 72, 61, 6D, 20, 63, 61, 6E, 6E, 6F, 74, 20, 62, 65, 20, 72, 75, 6E, 20, 69, 6E, 20, 44, 4F, 53, 20, 6D, 6F, 64, 65, 2E, 0D, 0D, 0A, 24, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.0508

Code size:
2.3 MB (2,411,520 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Threat Support Anti-Malware

Command:
"C:\Program Files\threat support\threat support anti-malware\tsantimalware.exe" \tray


Scan tsantimalware.exe - Powered by Reason Core Security