1bed3fd2-1989-4f8c-999a-fc4165449705.exe

TheTorntv V10

Nickel Cycle Combo

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The application 1bed3fd2-1989-4f8c-999a-fc4165449705.exe, “TheTorntv V10 exe” by Nickel Cycle Combo has been detected as adware by 24 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:
esc  (signed by Nickel Cycle Combo)

Product:
TheTorntv V10

Description:
TheTorntv V10 exe

Version:
1000.1000.1000.1000

MD5:
36dafb530dce0f3949bb89291b4be27b

SHA-1:
43898e7258f543e16d0856eb8f646e557be2f5fe

SHA-256:
b44ed3a631e0e8d4d273d6ae641afc209c1c62c8b1bc6490ad603684d04fcb16

Scanner detections:
24 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements. Distributed through the Brightcircle investments brand.

Analysis date:
4/26/2024 12:34:34 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Zusy.105499
838

AhnLab V3 Security
PUP/Win32.CrossRider
2014.10.10

Avira AntiVirus
ADWARE/CrossRider.Gen
7.11.183.246

avast!
Win32:Crossrider-AI [PUP]
2014.9-141218

AVG
Morgan
2015.0.3257

Baidu Antivirus
PUA.Win32.CrossRider
4.0.3.141218

Bitdefender
Gen:Variant.Adware.Zusy.105499
1.0.20.1460

Dr.Web
Trojan.Crossrider.36303
9.0.1.0352

Emsisoft Anti-Malware
Gen:Variant.Adware.Zusy.105499
8.14.10.19.05

ESET NOD32
Win32/Toolbar.CrossRider.BC (variant)
8.10701

F-Prot
W32/S-9ad4719b
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Zusy.105499
11.2014-19-10_1

G Data
Gen:Variant.Adware.Zusy.105499
14.10.24

Kaspersky
not-a-virus:AdWare.NSIS.Adwapper
14.0.0.2778

Malwarebytes
PUP.Optional.TornTV.A
v2014.10.19.05

McAfee
Artemis!36DAFB530DCE
5600.6972

MicroWorld eScan
Gen:Variant.Adware.Zusy.105499
15.0.0.876

NANO AntiVirus
Trojan.Win32.Crossrider.dgxrtw
0.28.6.62995

Panda Antivirus
Trj/Genetic.gen
14.10.19.05

Qihoo 360 Security
HEUR/Malware.QVM10.Gen
1.0.0.1015

Reason Heuristics
PUP.Crossrider.Task.e
14.10.19.17

Vba32 AntiVirus
Trojan.GoogUpdate
3.12.26.3

VIPRE Antivirus
Crossrider
33792

Zillya! Antivirus
Trojan.GoogUpdate.Win32.4301
2.0.0.1980

File size:
326.4 KB (334,240 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
TheTorntv V10.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\thetorntv v10\1bed3fd2-1989-4f8c-999a-fc4165449705.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/28/2014 2:00:00 AM

Valid to:
8/29/2015 1:59:59 AM

Subject:
CN=Nickel Cycle Combo, O=Nickel Cycle Combo, STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E88B19F4C25DE21197EE9D01573D202A

File PE Metadata
Compilation timestamp:
10/7/2014 9:32:39 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:8AWPFSIX/XmfgntkZ+dLX+p2vsIxQO3iPnujOR23695i0h1nSpTBf0Q+gLNdhx6C:8Aa1pnqZSyjMZ3Cnay5x1SpTBRBNEcKA

Entry address:
0x24510

Entry point:
E8, 1E, AA, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, 57, 56, 53, 33, FF, 8B, 44, 24, 14, 0B, C0, 7D, 14, 47, 8B, 54, 24, 10, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 14, 89, 54, 24, 10, 8B, 44, 24, 1C, 0B, C0, 7D, 14, 47, 8B, 54, 24, 18, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 1C, 89, 54, 24, 18, 0B, C0, 75, 18, 8B, 4C, 24, 18, 8B, 44, 24, 14, 33, D2, F7, F1, 8B, D8, 8B, 44, 24, 10, F7, F1, 8B, D3, EB, 41, 8B, D8, 8B, 4C, 24, 18, 8B, 54, 24, 14, 8B, 44, 24, 10, D1, EB, D1, D9, D1, EA, D1, D8, 0B...
 
[+]

Code size:
231.5 KB (237,056 bytes)

Scheduled Task
Task name:
1bed3fd2-1989-4f8c-999a-fc4165449705

Trigger:
Logon (Runs on logon)


Remove 1bed3fd2-1989-4f8c-999a-fc4165449705.exe - Powered by Reason Core Security