BitTorrent.exe

BitTorrent

BitTorrent Inc

This is a setup program which is used to install the application. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘BitTorrent’. This is installed with BitTorrent. The file has been seen being downloaded from www.download3k.com and multiple other hosts.
Publisher:
BitTorrent Inc.  (signed by BitTorrent Inc)

Product:
BitTorrent

Version:
7.9.5.41373

MD5:
8e686e2a4c1f32575d9dec9ddc4b711d

SHA-1:
ac60e08b8b46b1416cf5d8d60f29f19deb37a2ff

SHA-256:
4f5efab136240deb5c1e82ee46518b294856bd35797a327984e92911c9c029d9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 2:04:11 AM UTC  (today)

File size:
1.8 MB (1,877,792 bytes)

Product version:
7.9.5.41373

Copyright:
©2015 BitTorrent, Inc. All Rights Reserved.

Original file name:
BitTorrent.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\bittorrent\bittorrent.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/4/2013 5:00:00 PM

Valid to:
9/3/2016 4:59:59 PM

Subject:
CN=BitTorrent Inc, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=BitTorrent Inc, L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5732C1574E6AF828E1B4F93ABB34ED08

File PE Metadata
Compilation timestamp:
11/17/2015 12:24:18 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
24576:VW87aVgu14dlJfTwZcjqi9jgM4TOvtcGyxUTJm5MJ3MRXzPcjbhiHdHdAoJAh6sA:bJdfMcuvTOVcbvm8R45mHdlAh6sVLrQF

Entry address:
0x4A77C0

Entry point:
60, BE, 00, E0, 6F, 00, 8D, BE, 00, 30, D0, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, C6, 5B, 4A, 00, 57, 83, C3, 04, 53, 68, B0, 97, 1A, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Entropy:
7.9831  (probably packed)

Code size:
1.7 MB (1,748,992 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
BitTorrent

Command:
"C:\users\{user}\appdata\roaming\bittorrent\bittorrent.exe" \minimized


The file BitTorrent.exe has been discovered within the following program.

BitTorrent  by BitTorrent Inc.
BitTorrent is a desktop application that allows you to work with torrent files.BitTorrent allows you to download files available as torrents, search torrent sites for music, videos, books, software and other free or public domain material.
www.bittorrent.com
7% remove it
 
Powered by Should I Remove It?

The file BitTorrent.exe has been seen being distributed by the following 14 URLs.

http://www.download3k.com/DownloadLink1-BitTorrent.html

http://r2.computerbild.de/exec/r2r.pl?m=w-cobi;u=http://d.computerbild.de/downloads/.../BitTorrent.exe

Scan BitTorrent.exe - Powered by Reason Core Security