tv.exe

Cyberservices B.V.

Part of the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application tv.exe by Cyberservices B.V has been detected as adware by 10 anti-malware scanners. The file has been seen being downloaded from www.tvexe.com.
Publisher:
Cyberservices B.V.  (signed and verified)

MD5:
26860e5fa4aeb3bbe66fdc62362c1107

SHA-1:
7d11a9d6625ccbb1d9bcc15f1c7ffa009ab19a9c

SHA-256:
93b5db8cd7ab8ccfa071c2b296bbb3416a3793bffb7637099b65752e4e55240d

Scanner detections:
10 / 68

Status:
Adware

Analysis date:
4/26/2024 3:23:07 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

AVG
Cyberservices
2016.0.3209

Dr.Web
Adware.Downware.9662
9.0.1.05190

ESET NOD32
Win32/DownloadGuide.D potentially unwanted application
7.0.302.0

IKARUS anti.virus
PUA.DownloadGuide
t3scan.1.8.6.0

K7 AntiVirus
Unwanted-Program
13.193.14857

Malwarebytes
PUP.Optional.DownloadGuide
v2015.02.04.06

NANO AntiVirus
Trojan.Win32.DownloadGuide.dmcqvz
0.30.0.65070

Reason Heuristics
PUP.Outbrowse
15.2.4.6

VIPRE Antivirus
Threat.4150696
36694

File size:
588.6 KB (602,704 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\My documents\downloads\tv.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/10/2014 8:00:00 AM

Valid to:
2/11/2016 7:59:59 AM

Subject:
CN=Cyberservices B.V., O=Cyberservices B.V., STREET=Keizersgracht 62-64 NL, L=Amsterdam, S=Nordholland, PostalCode=1015CS, C=NL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
797CAC4561E8B8B21910CD01E0002669

File PE Metadata
Compilation timestamp:
1/5/2015 5:46:08 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:up8ytCJJYh/33L+LUkKRbl8jl2oWCoTBuVX1O1l43Xq:u/eonL+LfubCprKTAVFO1laXq

Entry address:
0x232B1

Entry point:
E8, 4C, 66, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 53, 56, 8B, F1, 33, DB, 3B, F3, 75, 16, E8, CD, 19, 00, 00, 6A, 16, 5E, 89, 30, E8, 71, 19, 00, 00, 8B, C6, E9, 8F, 00, 00, 00, 57, 39, 5D, 08, 77, 13, E8, B1, 19, 00, 00, 6A, 16, 5E, 89, 30, E8, 55, 19, 00, 00, 8B, C6, EB, 75, 33, C9, 39, 5D, 10, 88, 1E, 0F, 95, C1, 41, 39, 4D, 08, 77, 09, E8, 8E, 19, 00, 00, 6A, 22, EB, DB, 8B, 4D, 0C, 83, C1, FE, 83, F9, 22, 77, C9, 8B, CE, 39, 5D, 10, 74, 0B, 33, DB, 43, C6, 06, 2D, 8D, 4E, 01, F7, D8, 8B, F9...
 
[+]

Entropy:
6.9662

Code size:
323.5 KB (331,264 bytes)

The file tv.exe has been seen being distributed by the following URL.

Remove tv.exe - Powered by Reason Core Security