torntv v9.0-bho64.dll

Torntv V9.0

installdaddy

This web browser extension uses the Crossrider toolbar creation and distribution platform. The module torntv v9.0-bho64.dll has been detected as adware by 5 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘CrossriderApp0051390’. This file is typically installed with the program Torntv V9.0 by InstallDaddy Services Ltd. which is a potentially unwanted software program. This is the 64-bit verison of the Browser Helper Object (BHO) for the Crossrider web browser platform for Internet Explorer. Instead of utilizing a traditional IE Toolbar, Crossrider installs a BHO in the browser in order to manage the functionality of installdaddy addon.
Publisher:
installdaddy

Product:
Torntv V9.0

Description:
Torntv V9.0 BHO

Version:
1000.1000.1000.1000

MD5:
e3b01ac4b0c72b1cbe90e487fa132a7c

SHA-1:
0e6535ba04e59ad96e95f8fadf5fb352f98d767a

SHA-256:
d9f6ae2dad995515e155701bd333e2a566f70dfc112b52299943ac69d21be2e4

Scanner detections:
5 / 68

Status:
Adware

Explanation:
InstallDaddy bunldes adware such as toolbars and unwanted browser extensions.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application.

Analysis date:
2/19/2014 6:55:57 PM UTC  (six months ago)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win64.Crossrider
4.0.3.14219

ESET NOD32
Win64/Toolbar.Crossrider (variant)
8.9444

Malwarebytes
PUP.Optional.TornTV.A
v2014.02.19.01

Reason Heuristics
PUP.installdaddy.Q
14.2.18.16

VIPRE Antivirus
Crossrider
26632

File size:
927 KB (949,248 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
Torntv V9.0.dll

File type:
Dynamic link library (Win64 DLL)

Language:
English (United States)

Common path:
C:\Program Files\torntv v9.0\torntv v9.0-bho64.dll

Registration
CLSIDs:
{11111111-1111-1111-1111-110511131190}, {22222222-2222-2222-2222-220522132290}

ProgIDs:
CrossriderApp0051390.BHO.1, CrossriderApp0051390.Sandbox.1

COM registered:
Yes

File PE Metadata
Compilation timestamp:
2/4/2014 2:16:13 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:zRHcCOTo0swkPETYBKubKT2OIzxkPTfs2lTmMvUQfoq:zRBLmYU9Sxl6TTfvz

Entry address:
0x75CAC

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, 6F, D3, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, 03, 00, 00, 00, CC, CC, CC, 48, 8B, C4, 48, 89, 58, 20, 4C, 89, 40, 18, 89, 50, 10, 48, 89, 48, 08, 56, 57, 41, 56, 48, 83, EC, 50, 49, 8B, F0, 8B, DA, 4C, 8B, F1, BA, 01, 00, 00, 00, 89, 50, B8, 85, DB, 75, 0F, 39, 1D, 70, A3, 06, 00, 75, 07, 33, C0, E9, D2, 00, 00, 00, 8D, 43, FF...
 
[+]

Entropy:
6.1494

Code size:
617.5 KB (632,320 bytes)

Internet Explorer BHO
Display name:
CrossriderApp0051390

CLSID:
{11111111-1111-1111-1111-110511131190}

CLSID name:
Torntv V9.0


The file torntv v9.0-bho64.dll has been discovered within the following program.

Torntv V9.0  by InstallDaddy Services Ltd.
This is a potentially unwanted program (PUP) that bundles various additional offers during setup, typically ad-supported (adware) in functionality.
88% remove it
 
Powered by Should I Remove It?

There are 8 known variations of torntv v9.0-bho64.dll by installdaddy.

4 / 68      (Adware)
torntv v9.0-bho64.dll  1000.1000.1000.1000  (204faeadddb32e0292f9de44d72c01123f6fac11)

5 / 68      (Adware)
torntv v9.0-bho64.dll  1000.1000.1000.1000  (c4f0771dc96a0103613f6073044d5cc3ccc67e86)

6 / 68      (Adware)
torntv v9.0-bho64.dll  1000.1000.1000.1000  (0a800e3ec66347b63756f3bb53a722a00c9f9f57)

10 / 68    (Adware)
torntv v9.0-bho64.dll  1000.1000.1000.1000  (78d2d589e3de38f36c7ccaf573478d03e6b5eb47)

10 / 68    (Adware)
torntv v9.0-bho64.dll  1000.1000.1000.1000  (c2d448a556fe9f324b47292400bb8109802a59a9)

10 / 68    (Adware)
torntv v9.0-bho64.dll  1000.1000.1000.1000  (f8d5acc4720e40ef93bed7c8337a7a38dd052ba5)

4 / 68      (Adware)
torntv v9.0-bho64.dll  1000.1000.1000.1000  (41d507cfad7ff775d54480fd52a49fb2c44e5133)

3 / 68      (Adware)
torntv v9.0-bho64.dll  1000.1000.1000.1000  (34c003df04cdf9d118ba5addbbeebb7b5253fb60)

6 / 68      (Adware)
torntv v9.0-bho.dll  (80021702159c7bb74d04003ebd232f78a729b718)

8 / 68      (Adware)
torntv v9.0-bg.exe  (80331adc8be71a497a52c3108d1c1b9b8ab78a4f)

7 / 68      (Adware)
torntv v9.0-buttonutil.exe  (1e4605a46a19fe32b33c4e1e92b4804cb3c17e39)

7 / 68      (Adware)
torntv v9.0-chromeinstaller.exe  (164024380b912b28e7e0f2466a86b4837ab5e758)

6 / 68      (Adware)
torntv v9.0-codedownloader.exe  (05089b783441f86581217da7c9df6beb5e7be154)

6 / 68      (Adware)
torntv v9.0-enabler.exe  (8e51f1232ed9c8ab4d5a89f6a2d56521e699da99)

11 / 68    (Adware)
torntv v9.0-firefoxinstaller.exe  (00171e1a105ae7cc15d7b091b4fb8e24d7cca4d9)

7 / 68      (Adware)
torntv v9.0-updater.exe  (0bd9be34c5c8ada577686091a19be36607579a28)

3 / 68      (Adware)
torntv v9.0-buttonutil64.exe  (2ca1c891b6b4f034733d6ec66a8fb3a7a09ef388)

5 / 68      (Adware)
e2778b28-928c-4697-894d-65311608041e-2.exe  (3fec874ee87dcb52a09766139d7a663c5b9207de)

3 / 68      (Adware)
e2778b28-928c-4697-894d-65311608041e-3.exe  (7accbde3cb3661aedb3b55dd7299aa0a17b51b7d)

5 / 68      (Adware)
e2778b28-928c-4697-894d-65311608041e-4.exe  (1a57aab2ae30c1c7b51752fba2eaca5d20d23b44)

4 / 68      (Adware)
e2778b28-928c-4697-894d-65311608041e-5.exe  (10b71a3c7c3e30780429f5fd04d5781298389f9c)

Detection Incidence by Country