torntvdownloader4.exe

The application torntvdownloader4.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Nullsoft Scriptable Install System installer, however the file is not signed with an authenticode signature from a trusted source. The setup installer will bundle multiple adware offers during download and setup (based on the user's geographical location) including toolbars, extensions and coupon utilities.
MD5:
efaf5a3a54e1914c9011a8c6cd219cc0

SHA-1:
f66f4d3adcc5273aab5aaa48b9367fdea1c757d0

SHA-256:
768eaa0dee3007ec91ca88626ea3fac145b97c1aef3c80923a0577052d7495f8

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Bundles a number of adware programs in the installer.

Analysis date:
11/30/2024 8:00:31 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.CoolMirage.Installer.Meta (M)
16.4.15.9

File size:
357.6 KB (366,136 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Scriptable Install System

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\torntvdownloader4.exe

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:AQfPn8h4lFO90qrb+gn+4qUtoW1hAP9p/FqipXvV6VRHe3C13Fi7ik/WkofZY4+x:z8h4LMrnGUV1hu9JR5i1ro

Entry address:
0x30CB

Entry point:
60, 8D, 05, 95, C4, 6A, 9E, 0F, AF, C9, BA, 10, 37, 00, E7, 75, 08, 0D, 2C, AF, 16, 84, 0F, BE, C0, 0F, AF, F9, EB, 03, F6, C3, A1, C7, C0, C1, 5C, F2, 87, E8, 11, 00, 00, 00, BA, C5, 3D, C6, F5, B1, 51, FE, C6, 69, E9, 8D, 5C, 0F, A6, 3B, C7, 78, 02, 84, D2, FE, CD, 84, D5, F3, 85, F7, 8D, 1D, FE, 17, 53, C3, 68, B7, 0E, 00, 00, 69, FE, 34, 14, 29, 6E, 5E, 48, 0F, AF, DB, 69, FF, 22, 4E, 8D, 8B, 81, F6, 5F, 08, 00, 00, 73, 07, 86, CA, 85, F2, 0F, B6, EE, 8B, D5, BF, 61, A3, 7A, 20, F2, F7, C7, F1, 78, BD...
 
[+]

Entropy:
7.9427  (probably packed)

Code size:
22.5 KB (23,040 bytes)

The file torntvdownloader4.exe has been seen being distributed by the following URL.

Remove torntvdownloader4.exe - Powered by Reason Core Security