BTSync.exe

BitTorrent Sync

BitTorrent Inc

This is a setup program which is used to install the application. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘BitTorrent Sync’. This is installed with multiple programs including BitTorrent Sync. The file has been seen being downloaded from download-lb.utorrent.com and multiple other hosts.
Publisher:
BitTorrent, Inc.  (signed by BitTorrent Inc)

Product:
BitTorrent Sync

Version:
1.1.82

MD5:
439a02e41120cc1cadd376d98a5ed6f8

SHA-1:
eaabbbea7a1609bfecef5c0b30e5f026bcfd516a

SHA-256:
61497a58c7106bc3ac5c199a3656f962c0ce548e20bc01a55b8b5005545c03cc

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 8:50:41 AM UTC  (today)

File size:
1.5 MB (1,538,920 bytes)

Product version:
1.1.82

Copyright:
Copyright (C) 2013 BitTorrent, Inc. All Rights Reserved.

Original file name:
BTSync.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\bittorrent sync\btsync.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/4/2013 8:00:00 PM

Valid to:
9/3/2016 7:59:59 PM

Subject:
CN=BitTorrent Inc, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=BitTorrent Inc, L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5732C1574E6AF828E1B4F93ABB34ED08

File PE Metadata
Compilation timestamp:
9/23/2013 3:58:51 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:ZiqD71chgSzW+NMvW167eHUz3x2+ygYkeZgT4VhHXjOgxfY0bq+VoavRs+:N7+hgSzxV0NtYkXMPH9fTqsps+

Entry address:
0x295F80

Entry point:
60, BE, 00, 90, 53, 00, 8D, BE, 00, 80, EC, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, B7, 3D, 29, 00, 57, 83, C3, 04, 53, 68, 79, CF, 15, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Entropy:
7.9787  (probably packed)

Code size:
1.4 MB (1,433,600 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
BitTorrent Sync

Command:
"C:\Program Files\bittorrent sync\btsync.exe" \minimized


Windows Firewall Allowed Program
Name:
C:\Documents and Settings\A.Imane\Local Settings\Temp\BTSync_copy.exe


The file BTSync.exe has been discovered within the following programs.

BitTorrent Sync  by BitTorrent, Inc.
Publisher's description - “Sync files between mobile devices, collaborators, or your home and work PC. Want to share and sync files on the go? BitTorrent Sync lets you share files with family and friends, share files between mobile devices, and backup your phone and tablets.”
labs.bittorrent.com/experiments/sync.html
About 3% of users remove it
FeralHeart version 1.13  by Kovuworks
feral-heart.com
About 6% of users remove it
 
Powered by Should I Remove It?

The file BTSync.exe has been seen being distributed by the following 2 URLs.

Scan BTSync.exe - Powered by Reason Core Security