tvnserver.exe

TightVNC

GlavSoft LLC.

The executable tvnserver.exe, “TightVNC Server for Windows” has been detected as malware by 12 anti-virus scanners. It runs as a separate (within the context of its own process) windows Service named “TightVNC Server”.
Publisher:
GlavSoft LLC.  (signed and verified)

Product:
TightVNC

Description:
TightVNC Server for Windows

Version:
2.0.4.0

MD5:
ae7cd6d68f3223803dd532a20f6a95bd

SHA-1:
41bad25b575c396e127b77657e490a6155684e06

SHA-256:
7cea7fabbfada3711a422b2375aa50e22d3ef9236425e031a9acf9fdab4c3392

Scanner detections:
12 / 68

Status:
Malware

Analysis date:
11/23/2024 9:35:03 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Pioneer-C
160326-0

AVG
Win32/Floxif.A
2015.0.4568

Dr.Web
Win32.FloodFix.7
9.0.1.05190

Emsisoft Anti-Malware
Win32.Floxif
11.5.0.6191

ESET NOD32
Win32/Floxif.H virus
8.0.319.0

F-Prot
W32/Floxif.B
4.6.5.141

F-Secure
Win32.Floxif.A
5.15.21

Kaspersky
Virus.Win32.Pioneer
15.0.0.562

McAfee
Trojan.Dropper-FIY!AE7CD6D68F32
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.219.1878.0

Norman
Win32.Floxif.A
10.04.2016 15:29:17

Sophos
Virus 'W32/Floxif-C'
5.23

File size:
886 KB (907,223 bytes)

Product version:
2.0.4.0

Copyright:
Copyright (C) 2008-2011 GlavSoft LLC.

Original file name:
tvnserver.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\tightvnc\tvnserver.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
3/30/2011 6:00:00 AM

Valid to:
3/30/2012 5:59:59 AM

Subject:
CN=GlavSoft LLC., O=GlavSoft LLC., L=Tomsk, S=Tomsk, C=RU

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
387FDDE484885E7290821D874F860703

File PE Metadata
Compilation timestamp:
8/3/2011 7:18:06 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:gHwsfthv30UsjD/ANmqFSjBxh3I+JrQsHxcZq8mxMD2pJ7XJBjvrEH7sPa:Ofthv3HsIsqMBdJrBHxcZq8mKOzrEH7j

Entry address:
0x64414

Entry point:
E9, 96, C3, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 14, 56, 57, 33, FF, 3B, C7, 74, 47, 39, 7D, 08, 75, 1B, E8, 2F, 2E, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, 8D, 02, 00, 00, 83, C4, 14, 8B, C6, EB, 29, 39, 7D, 10, 74, E0, 39, 45, 0C, 73, 0E, E8, 0A, 2E, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, D7, 50, FF, 75, 10, FF, 75, 08, E8, 2E, 0F, 00, 00, 83, C4, 0C, 33, C0, 5F, 5E, 5D, C3, 8B, C1, 83, 60, 04, 00, 83, 60, 08, 00, C7, 00, 88, 15, 48, 00, C3, 8B, FF, 55, 8B, EC, 53, 8B, 5D...
 
[+]

Entropy:
6.7352

Packer / compiler:
Xtreme-Protector v1.05

Code size:
510.5 KB (522,752 bytes)

Service
Display name:
TightVNC Server

Service name:
tvnserver

Type:
Win32OwnProcess


Remove tvnserver.exe - Powered by Reason Core Security