tv.exe

Cyberservices B.V.

Part of the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application tv.exe by Cyberservices B.V has been detected as adware by 6 anti-malware scanners. The file has been seen being downloaded from www.tvexe.com.
Publisher:
Cyberservices B.V.  (signed and verified)

MD5:
a59b083241ba33933dfd4eee4891607f

SHA-1:
54e67e8cf9aedbe7eaae78ae3ba1db80f46a6ff2

SHA-256:
93e9eae697f2ca994a5bea5ce89cebaac7841d3807a037768227965ed4ab7c22

Scanner detections:
6 / 68

Status:
Adware

Analysis date:
4/25/2024 8:13:58 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Cyberservices
2016.0.3223

ESET NOD32
Win32/DownloadGuide.D potentially unwanted application
7.0.302.0

K7 AntiVirus
Unwanted-Program
13.191.14703

NANO AntiVirus
Trojan.Win32.DownloadGuide.dmjzno
0.30.0.64812

Reason Heuristics
PUP.Outbrowse
15.1.20.14

VIPRE Antivirus
Threat.4150696
36694

File size:
602.1 KB (616,544 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/9/2014 4:00:00 PM

Valid to:
2/10/2016 3:59:59 PM

Subject:
CN=Cyberservices B.V., O=Cyberservices B.V., STREET=Keizersgracht 62-64 NL, L=Amsterdam, S=Nordholland, PostalCode=1015CS, C=NL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
797CAC4561E8B8B21910CD01E0002669

File PE Metadata
Compilation timestamp:
1/14/2015 8:42:25 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:0ID1N/OdE7zkN0TgM6hTV960Yu6OY3P0bxJkBzcZMW9+/6RuVX1SNG997rEWcYu6:RfB8yTgM6hTV960Yu6OYBBzcZMW9+/6Y

Entry address:
0x24831

Entry point:
E8, BC, 66, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 53, 56, 8B, F1, 33, DB, 3B, F3, 75, 16, E8, 08, 1C, 00, 00, 6A, 16, 5E, 89, 30, E8, AC, 1B, 00, 00, 8B, C6, E9, 8F, 00, 00, 00, 57, 39, 5D, 08, 77, 13, E8, EC, 1B, 00, 00, 6A, 16, 5E, 89, 30, E8, 90, 1B, 00, 00, 8B, C6, EB, 75, 33, C9, 39, 5D, 10, 88, 1E, 0F, 95, C1, 41, 39, 4D, 08, 77, 09, E8, C9, 1B, 00, 00, 6A, 22, EB, DB, 8B, 4D, 0C, 83, C1, FE, 83, F9, 22, 77, C9, 8B, CE, 39, 5D, 10, 74, 0B, 33, DB, 43, C6, 06, 2D, 8D, 4E, 01, F7, D8, 8B, F9...
 
[+]

Entropy:
6.9864

Code size:
327 KB (334,848 bytes)

The file tv.exe has been seen being distributed by the following URL.

Remove tv.exe - Powered by Reason Core Security