ChrisTV_Agent.exe

ChrisTV Agent

Chris P.C. srl

The executable ChrisTV_Agent.exe has been detected as malware by 1 anti-virus scanner. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘ChrisTV Agent’.
Publisher:
Chris P.C. srl  (signed and verified)

Product:
ChrisTV Agent

Version:
2.0.5.20

MD5:
c5d9213307f5b5734472c3d87fa5a255

SHA-1:
1a1c2cc3ed30ebc8d89f3c45ef1f382afe5df7b3

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/27/2024 2:48:31 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.1.6.6

File size:
444 KB (454,616 bytes)

Product version:
2.0.5.19

Copyright:
Chris P.C. srl

Trademarks:
Chris P.C. srl

Original file name:
ChrisTV_Agent.exe

File type:
Executable application (Win32 EXE)

Language:
Roumain

Common path:
C:\Program Files\christv pvr standard\christv_agent.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
1/8/2013 1:00:00 AM

Valid to:
1/9/2016 12:59:59 AM

Subject:
CN=Chris P.C. srl, O=Chris P.C. srl, STREET=Nicolae Cristea 25/8, L=Cluj-Napoca, S=Cluj, PostalCode=400184, C=RO

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
319A47CF0068FDF122C7AC1163A961B8

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xC1000

Entry point:
BB, EE, 0A, 2B, 01, 90, 90, 68, 1E, 10, 4C, 00, 5E, 68, 98, 05, 00, 00, 5F, 90, 31, 1C, 3E, 83, EF, 02, 83, EF, 02, 90, 90, 75, F3, 90, 06, 77, 2A, 01, EE, 0A, 2B, 01, EE, 0A, 6B, 01, 3E, D4, 20, 01, 1E, 33, 2F, 01, 36, 35, 2F, 01, EE, BA, 29, 01, 11, F5, D4, FE, B6, 04, 67, 01, CE, 05, 67, 01, C0, 05, 67, 01, EE, 0A, 2B, 01, EE, 0A, 2B, 01, EE, 0A, 2B, 01, B6, 2E, 2F, 01, F0, 05, 27, 01, C2, 05, 27, 01, EE, 0A, 2B, 01, EE, 0A, 2B, 01, EE, 0A, 2B, 01, EE, 0A, 2B, 01, EE, 0A, 2B, 01, EE, 0A, 2B, 01, EE, 0A...
 
[+]

Code size:
260 KB (266,240 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ChrisTV Agent

Command:
"C:\Program Files\christv pvr standard\christv_agent.exe" \silent


Remove ChrisTV_Agent.exe - Powered by Reason Core Security