torntv 2-bg.exe

Torntv 2

installdaddy

The application torntv 2-bg.exe has been detected as adware by 24 anti-malware scanners. This file is typically installed with the program Torntv 2 by InstallDaddy Services Ltd. which is a potentially unwanted software program. Part of the Corssrider web browser platform, the BG executable is a background process that manage various function of the installed extensions in user's browser including managing installation, updates and remote code downloads. While running, it connects to the Internet address sage.parklogic.com on port 80 using the HTTP protocol.
Publisher:
installdaddy

Product:
Torntv 2

Description:
Torntv 2 exe

Version:
1000.1000.1000.1000

MD5:
0cfd3109fba9c2fbe8e7ec1bcafc0ff2

SHA-1:
09d98fd35ce29d438858ce9fa0d4ebbde4f47777

SHA-256:
38a75b7396d53b515662130fec4490c372e85cfb06b7c2082bf721c3f4e77a8a

Scanner detections:
24 / 68

Status:
Adware

Explanation:
InstallDaddy bunldes adware such as toolbars and unwanted browser extensions.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application.

Analysis date:
12/26/2024 5:00:34 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Generic.607093
1036

Agnitum Outpost
Adware.Lyckriks
7.1.1

avast!
Win32:Downloader-UMN [Drp]
2014.9-140129

Baidu Antivirus
Adware.Win32.AddLyrics
4.0.3.1445

Bitdefender
Adware.Generic.582502
1.0.20.145

Bkav FE
W32.Clodca1.Trojan
1.3.0.4923

Dr.Web
Trojan.Crossrider.1
9.0.1.029

Emsisoft Anti-Malware
Adware.Generic.582502
8.14.01.29.03

ESET NOD32
Win32/Toolbar.CrossRider (variant)
8.9040

Fortinet FortiGate
Adware/Lyckriks
1/29/2014

F-Secure
Adware.Generic.582502
11.2014-29-01_4

G Data
Adware.Generic.582502
14.1.22

herdProtect (fuzzy)
2014.4.5.10

IKARUS anti.virus
not-a-virus:AdWare.Win32.Lyckriks
t3scan.2.2.29

K7 AntiVirus
Adware
13.173.10176

Kaspersky
not-a-virus:AdWare.Win32.Lyckriks
14.0.0.4394

McAfee
Artemis!31E72869E0A8
5600.7170

MicroWorld eScan
Adware.Generic.582502
15.0.0.87

NANO AntiVirus
Trojan.Win32.Crossrider.cqkogt
0.28.0.57380

nProtect
Trojan-Clicker/W32.Lyckriks.896000
13.11.12.01

Reason Heuristics
PUP.Crossrider.installdaddy.L
14.3.6.15

Sophos
Generic PUA AJ
4.94

Vba32 AntiVirus
AdWare.Lyckriks
3.12.24.3

VIPRE Antivirus
Crossrider
23312

File size:
875 KB (896,000 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
Torntv 2.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\torntv 2\torntv 2-bg.exe

File PE Metadata
Compilation timestamp:
6/10/2013 8:07:22 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:7tc2DxJQ5kIxaiGC53kYcaVpTe6ghTzjW7q:7tc35kliGC53aaO6ghTfW7q

Entry address:
0x76983

Entry point:
E8, 66, AD, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 33, C9, 3B, 04, CD, E8, 80, 4D, 00, 74, 13, 41, 83, F9, 2D, 72, F1, 8D, 48, ED, 83, F9, 11, 77, 0E, 6A, 0D, 58, 5D, C3, 8B, 04, CD, EC, 80, 4D, 00, 5D, C3, 05, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8, 1B, C0, 23, C1, 83, C0, 08, 5D, C3, E8, 52, 0E, 00, 00, 85, C0, 75, 06, B8, 50, 82, 4D, 00, C3, 83, C0, 08, C3, E8, 3F, 0E, 00, 00, 85, C0, 75, 06, B8, 54, 82, 4D, 00, C3, 83, C0, 0C, C3, 8B, FF, 55, 8B, EC, 56, E8, E2, FF, FF, FF, 8B, 4D, 08...
 
[+]

Entropy:
6.5475

Code size:
711.5 KB (728,576 bytes)

The file torntv 2-bg.exe has been discovered within the following program.

Torntv 2  by InstallDaddy Services Ltd.
Torntv 2 uses the Installdaddy download and install manager which is designed to co-bundle additional offers which include toolbars, web browser extensions as well as various potentially unwanted applications.
www.installdaddy.com
70% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to sage.parklogic.com  (69.39.236.56:80)

Remove torntv 2-bg.exe - Powered by Reason Core Security