ttsvc.exe

Term Tutor Client Service

Termtutor, LLC

This is part of the InfoAtoms browser extension which will display variopus forms of advertising in the web browser by injecting new ads such as banner, text-links and search results. The application ttsvc.exe by Termtutor has been detected as adware by 18 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Term Tutor Client Service”. This file is typically installed with the program Term Tutor which is a potentially unwanted software program.
Publisher:
Term Tutor  (signed by Termtutor, LLC)

Product:
Term Tutor Client Service

Version:
1.9.0.8

MD5:
c86ceb3838e7b5fa0ebf54b6a1e68c9b

SHA-1:
f48e3296587da40fdce135488ec1cfdab4f77ceb

SHA-256:
1b7ebf2c2e8e6a48c0269b508a8550a8b16aa449881455ed35a8dbdeb6e2486a

Scanner detections:
18 / 68

Status:
Adware

Analysis date:
12/24/2024 5:01:25 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Vitruvian.B
794

Agnitum Outpost
PUA.Vitruvian
7.1.1

AVG
Snacks
2015.0.3272

Baidu Antivirus
Adware.Win32.Vitruvian
4.0.3.14122

Bitdefender
Adware.Vitruvian.B
1.0.20.1680

Comodo Security
ApplicUnwnt
20073

Emsisoft Anti-Malware
Adware.Vitruvian
8.14.12.02.07

ESET NOD32
Win32/AdWare.Vitruvian (variant)
8.10386

Fortinet FortiGate
Riskware/Vitruvian
12/2/2014

F-Secure
Adware.Vitruvian.B
11.2014-02-12_3

G Data
Adware.Vitruvian
14.12.24

IKARUS anti.virus
PUA.Vitruvian
t3scan.1.8.3.0

MicroWorld eScan
Adware.Vitruvian.B
15.0.0.1008

nProtect
Adware.Vitruvian.B
14.11.13.01

Reason Heuristics
PUP.Service.Termtutor.F
14.11.20.9

Sophos
Generic PUA KJ
4.98

Trend Micro House Call
Suspicious_GEN.F47V1015
7.2.336

VIPRE Antivirus
InfoAtoms
32942

File size:
269.6 KB (276,048 bytes)

Product version:
1.9.0.8

Copyright:
Copyright (C) 2014

Original file name:
ttsvc.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\termtutor\service\ttsvc.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
6/13/2014 12:14:10 PM

Valid to:
6/13/2016 12:14:10 PM

Subject:
E=support@termtutor.com, CN="Termtutor, LLC", O="Termtutor, LLC", L=La Jolla, S=CA, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121B4A9C8497F166386FF96F59F02D6FD46

File PE Metadata
Compilation timestamp:
9/4/2014 1:22:15 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

CTPH (ssdeep):
3072:ltbwHDPj3ZhOrReZ0Fo71GhN0ToRmfzkOthVaOOYG8K+5pqePXRK5+rqOWCTBfEg:lc9Z0neiOOhKYevRK56WCTBcSNRFe8

Entry address:
0x20BA8

Entry point:
E8, 53, 57, 00, 00, E9, 7B, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 0C, 57, 85, C9, 0F, 84, 92, 00, 00, 00, 56, 53, 8B, D9, 8B, 74, 24, 14, F7, C6, 03, 00, 00, 00, 8B, 7C, 24, 10, 75, 0B, C1, E9, 02, 0F, 85, 85, 00, 00, 00, EB, 27, 8A, 06, 83, C6, 01, 88, 07, 83, C7, 01, 83, E9, 01, 74, 2B, 84, C0, 74, 2F, F7, C6, 03, 00, 00, 00, 75, E5, 8B, D9, C1, E9, 02, 75, 61, 83, E3, 03, 74, 13, 8A, 06, 83, C6, 01, 88, 07, 83, C7, 01, 84, C0, 74, 37, 83, EB, 01, 75, ED, 8B, 44...
 
[+]

Entropy:
6.3145

Code size:
179 KB (183,296 bytes)

Service
Display name:
Term Tutor Client Service

Service name:
ttsvc

Description:
This service enables Term Tutor on HTTP websites

Type:
Win32OwnProcess


The file ttsvc.exe has been discovered within the following program.

Term Tutor  by Term Tutor
Term Tutor is a Window’s software program that is free and supported with ads.
www.termtutor.com
63% remove it
 
Powered by Should I Remove It?

Remove ttsvc.exe - Powered by Reason Core Security