uTorrent.exe

µTorrent

BitTorrent Inc

µTorrent is a free ad-supported lightweight BitTorrent client. This is a setup program which is used to install the application. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘uTorrent’. This is installed with µTorrent. The file has been seen being downloaded from kinoslivki.ru and multiple other hosts.
Publisher:
BitTorrent, Inc.  (signed by BitTorrent Inc)

Product:
µTorrent

Version:
3.2.0.27886

MD5:
2c1ef6485eeb834187fc69556a64eafe

SHA-1:
c959e7d82203d234eb4912c61f05a450417c8c36

SHA-256:
7f25b9bbec978f3f3810d1e064d2ca9330061bd9d0f7df9c3370f020e9d38e56

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/29/2024 10:32:53 AM UTC  (today)

File size:
875.9 KB (896,912 bytes)

Product version:
3.2.0.27886

Copyright:
©2012 BitTorrent, Inc. All Rights Reserved.

Original file name:
uTorrent.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\utorrent\utorrent.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/20/2010 9:00:00 PM

Valid to:
7/26/2013 8:59:59 PM

Subject:
CN=BitTorrent Inc, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=BitTorrent Inc, L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
36BC30562A650AFAA5AD101ECD643AB4

File PE Metadata
Compilation timestamp:
9/5/2012 7:44:31 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:CiJW6VgX0SyGUsp8Qd/zDdz+A+hi6+pE30vwmC46oSVISpn7awwgoSPh:CiJ/lGl6Qp3R+hos4w74YGwJh

Entry address:
0x514D60

Entry point:
60, BE, 00, 80, 87, 00, 8D, BE, 00, 90, B8, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, 46, 23, 51, 00, 57, 83, C3, 04, 53, 68, 51, CD, 09, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Code size:
632 KB (647,168 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
uTorrent

Command:
"C:\Program Files\utorrent\utorrent.exe" \minimized


Windows Firewall Allowed Program
Name:
C:\Arquivos de programas\uTorrent\uTorrent.exe


The file uTorrent.exe has been discovered within the following programs.

µTorrent  by BitTorrent Inc.
µTorrent is a is a free, ad-supported, lighter-weight BitTorrent client designed to consume less resources then the full BitTorrent version.
www.utorrent.com
12% remove it
iTunes  by Apple Inc.
Apple's iTunes is a proprietary media player computer program, used for playing and organizing digital music and video files on desktop computers. It can also manage contents on iPod, iPhone and iPad.
www.apple.com/itunes
9% remove it
 
Powered by Should I Remove It?

The file uTorrent.exe has been seen being distributed by the following 24 URLs.

http://kinoslivki.ru/.../utorrent.exe

http://www.afterdawn.com/software/.../download.cfm?version_id=51174&software_id=771&mirror_id=0&installer=0&perion=0

http://dc488.4shared.com/download/.../uTorrent.exe

http://software.oldversion.com/download.php?f=YTo1OntzOjQ6InRpbWUiO2k6MTQ2ODkzMDA1NztzOjI6ImlkIjtpOjgzMjQ7czo0OiJmaWxlIjtzOjI4OiJ1VG9ycmVudF8zLjJfYnVpbGRfMjc4ODYuZXhlIjtzOjM6InVybCI7czo1ODoiaHR0cDovL3d3dy5vbGR2ZXJzaW9uLmNvbS93aW5kb3dzL3V0b3JyZW50LTMtMi1idWlsZC0yNzg4NiI7czo0OiJwYXNzIjtzOjMyOiJmNmNjMDhiMTZmNDdlMzEyMWFiMDliY2U3MGYxNzU5NiI7fQ==

ftp://222.255.38.10/uTorrent.exe

Scan uTorrent.exe - Powered by Reason Core Security