ttpsvr.exe

ttpsvr Module

The file ttpsvr.exe has been detected as malware by 24 anti-virus scanners. It runs as a separate (within the context of its own process) windows Service named “vymmtatbdzqsoemuvnpp”.
Product:
ttpsvr Module

Version:
5, 9, 4, 0

MD5:
56d8e30c1fd9b11b26cabebc754edc2c

SHA-1:
7cac1a61d6c9757f28ef22f53ba8b6272f0c8b6c

Scanner detections:
24 / 68

Status:
Malware

Analysis date:
10/13/2025 2:01:11 PM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Troj.W32.Scar.mBLJ
2.1.4+

AhnLab V3 Security
Trojan/Win32.Scar.N621819587
3.7.4.14

Avira AntiVirus
TR/Nitol.A.707
8.3.3.4

avast!
Win32:Downloader-PTQ [Trj]
2014.9-170316

AVG
BackDoor.Generic_r
2018.0.2438

Bkav FE
HW32.Packed
1.3.0.8042

Comodo Security
TrojWare.Win32.Trojan.XPACK.Gen
25419

Dr.Web
Trojan.Encoder.378
9.0.1.075

ESET NOD32
Win32/ServStart.AD (variant)
11.13781

IKARUS anti.virus
Trojan.Win32.Nitol
t3scan.2.1.6.0

K7 AntiVirus
Riskware
13.232.20186

Kaspersky
Trojan.Win32.Scar
14.0.0.-1316

Malwarebytes
Trojan.ServStart
v2017.03.16.04

McAfee
Artemis!56D8E30C1FD9
5600.6094

Microsoft Security Essentials
DDoS:Win32/Nitol.A
1.1.12902.0

NANO AntiVirus
Trojan.Win32.DownLoader6.wnglg
1.0.38.8984

Panda Antivirus
Generic Malware
17.03.16.04

Qihoo 360 Security
Malware.Radar02.Gen
1.0.0.1120

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_SPNR.30BC13
7.2.75

Trend Micro
TROJ_SPNR.30BC13
10.465.16

Vba32 AntiVirus
Trojan.Lapka.1540A
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Nitol.b
50748

Zillya! Antivirus
Trojan.Scar.Win32.75320
2.0.0.2952

File size:
161.5 KB (165,376 bytes)

Product version:
5, 9, 4, 0

Copyright:
Copyright 2003-2012

Original file name:
ttpsvr.exe

Common path:
C:\windows\temp\hrl1.tmp

File PE Metadata
Compilation timestamp:
7/27/2012 1:44:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x446AA

Entry point:
68, E7, A2, 13, 22, E8, AA, 36, 00, 00, 68, 3F, 7C, 32, 23, E8, B9, 36, 00, 00, 40, 40, D1, 17, 7A, 42, 3C, 0C, 69, D0, 95, 6E, 12, 6A, 84, 3C, 96, 29, 20, ED, 89, 4D, 46, E7, DE, FD, D2, C7, 4D, 69, 32, C8, 8E, D3, 0E, 67, D9, 01, 1B, A5, 0C, 54, BB, 40, AA, 0A, 71, 3C, 15, 4B, 9D, AC, 43, 61, 8B, A2, 55, 56, A1, D4, C4, 0A, 56, 96, C4, D2, 06, C7, 93, 41, 2A, 5A, 7D, 4A, A0, 44, 9D, A3, D1, 67, 38, 0E, A8, D8, 28, EA, FF, 45, 69, 59, A7, 3E, 1E, 64, 72, D6, 55, 71, 36, AA, 5D, A6, 71, 1F, 35, FF, 43, 4B...
 
[+]

Entropy:
6.9329

Code size:
27.5 KB (28,160 bytes)

Service
Display name:
vymmtatbdzqsoemuvnpp

Service name:
eeddpszrna

Description:
psuacbazuxmhecthlegrpunkdmbppw

Type:
Win32OwnProcess


Remove ttpsvr.exe - Powered by Reason Core Security