torntvapp_setup_ch.exe

The application torntvapp_setup_ch.exe has been detected as a potentially unwanted program by 17 anti-malware scanners. The program is a setup application that uses the Self-extracting archive installer, however the file is not signed with an authenticode signature from a trusted source. The setup installer will bundle multiple adware offers during download and setup (based on the user's geographical location) including toolbars, extensions and coupon utilities. The file has been seen being downloaded from www.torntv-tvv.org and multiple other hosts.
MD5:
0b3a04cc0140da0cc7edb326d7f057ef

SHA-1:
790f5c8d101484119a1722159064106c871ceee0

SHA-256:
2872454d840091fe010c2650326d9482e16a475942ed03d38450ff452060c544

Scanner detections:
17 / 68

Status:
Potentially unwanted

Explanation:
Bundles a number of adware programs in the installer.

Analysis date:
4/23/2024 8:01:29 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/Downl.465087
7.11.137.202

Baidu Antivirus
Adware.Win32.1ClickDownload
4.0.3.141010

Bkav FE
W32.Cloda41.Trojan
1.3.0.4959

Comodo Security
Application.Win32.MCool.D
17951

Dr.Web
Adware.Downware.1263
9.0.1.0283

ESET NOD32
Win32/Adware.1ClickDownload.AO
8.9558

G Data
NSIS.Adware.OneClickDownloader
14.10.24

K7 AntiVirus
Adware
13.176.11482

Malwarebytes
PUP.Optional.OneClickDownloader.A
v2014.10.10.04

McAfee
Artemis!0B3A04CC0140
5600.6981

Microsoft Security Essentials
SoftwareBundler:Win32/OneClickDownloader
1.10401

NANO AntiVirus
Riskware.Script.Adware.cuhowq
0.28.0.58491

Panda Antivirus
PUP/MultiToolbar.A
14.10.10.04

Qihoo 360 Security
Trojan.Generic
1.0.0.1015

Sophos
CoolMirage
4.98

Trend Micro House Call
TROJ_GE.714718C3
7.2.283

VIPRE Antivirus
News.net
27514

File size:
454.2 KB (465,087 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Self-extracting archive

Common path:
C:\users\{user}\downloads\torntvapp_setup_ch.exe

File PE Metadata
Compilation timestamp:
4/28/2013 12:17:29 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:1XH38FA7I8C4dU5U2tsKI8UK3MrhRNTQ2vIdhM:JHMeq4dUrWb8OR5tvQhM

Entry address:
0x1CC88

Entry point:
E8, 99, 58, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 56, 8D, 45, 08, 50, 8B, F1, E8, 35, 24, 00, 00, C7, 06, 94, 71, 42, 00, 8B, C6, 5E, 5D, C2, 04, 00, C7, 01, 94, 71, 42, 00, E9, EA, 24, 00, 00, 8B, FF, 55, 8B, EC, 56, 8B, F1, C7, 06, 94, 71, 42, 00, E8, D7, 24, 00, 00, F6, 45, 08, 01, 74, 07, 56, E8, 80, CD, FF, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 56, 57, 8B, 7D, 08, 8B, 47, 04, 85, C0, 74, 47, 8D, 50, 08, 80, 3A, 00, 74, 3F, 8B, 75, 0C, 8B, 4E, 04, 3B, C1, 74, 14, 83, C1, 08...
 
[+]

Entropy:
7.6229

Code size:
147 KB (150,528 bytes)

The file torntvapp_setup_ch.exe has been seen being distributed by the following 6 URLs.

http://www.torntv-tvv.org/download/dldl.php?pub=ap772742-vertor&fileName=uggc://.../vaqrk.cuc?zbq=qbjaybnq&vq=1025640&name=Ovtsvfu Tnzrf - Rys Objyvat - Unjnvvna Inpngvba Nqana Obl 2008 Cerpenpxrq&sp=1

Remove torntvapp_setup_ch.exe - Powered by Reason Core Security