torrent.exe

WARP INSTALLER

The software uses a vraiant of the Adknowledge Optimum Installer to bundle additional offers in the setup routine including adware toolbars and extensions. This installer itself is just a download manager designed to present such offers (with minimal notice). The application torrent.exe, “Premium Installer ” by WARP INSTALLER has been detected as adware by 36 anti-malware scanners. The program is a setup application that uses the Adknowledge Fusion installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent.
Publisher:
Premium Installer   (signed by WARP INSTALLER)

Product:
Premium Installer

Description:
Premium Installer

Version:
2.4.8.1

MD5:
4d504d4d53aab438adb9f0a79fe88115

SHA-1:
d56cc36791795e145f2068696cdd7c7f0f022299

SHA-256:
64887c987b0b835c3ac038f6294e7957f762535217a22b75033910e81f1e9508

Scanner detections:
36 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/27/2024 4:20:50 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.Agent.B
413

Agnitum Outpost
PUA.Agent
7.1.1

AhnLab V3 Security
2014.09.29

Avira AntiVirus
APPL/OpenInst.pepuq
7.11.174.252

avast!
Win32:IBryte-CZ [PUP]
2014.9-151219

AVG
Adware AdPlugin
2016.0.2891

Bitdefender
Application.Bundler.Agent.B
1.0.20.1765

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Adware.Ibryte-236
0.98/19447

Comodo Security
Application.Win32.IBryte.Z
19645

Dr.Web
Trojan.Packed.28561
9.0.1.0353

Emsisoft Anti-Malware
Application.Bundler.Agent
8.15.12.19.08

ESET NOD32
Win32/AdWare.iBryte.AA application
9.7.0.302.0

Fortinet FortiGate
Riskware/Generic.AC.1188117
12/19/2015

F-Prot
W32/A-85132f45
v6.4.7.1.166

F-Secure
Application.Bundler.Agent
11.2015-19-12_7

G Data
Application.Bundler.Agent
15.12.24

IKARUS anti.virus
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.183.13504

Kaspersky
not-a-virus:AdWare.Win32.iBryte
14.0.0.948

Malwarebytes
v2015.12.19.08

McAfee
GenericATG-FGI!AB255E56E635
5600.6547

MicroWorld eScan
Application.Bundler.Agent.B
16.0.0.1059

NANO AntiVirus
Trojan.Win32.Badur.cxladi
0.28.2.62286

Norman
Application.Bundler.Agent.B
11.20151219

nProtect
Application.Bundler.Agent.B
14.09.28.01

Panda Antivirus
Trj/Genetic.gen
15.12.19.08

Qihoo 360 Security
Malware.QVM10.Gen
1.0.0.1015

Quick Heal
Adware.iBryte.DK4
12.15.14.00

Reason Heuristics
PUP.Adknowledge.WARPINSTALLER.Installer (M)
15.12.19.8

Rising Antivirus
PE:Malware.iBryte!6.192B
23.00.65.151217

SUPERAntiSpyware
PUP.OptimumInstaller/Variant
9438

Vba32 AntiVirus
3.12.26.3

VIPRE Antivirus
Threat.4150696
33120

Zillya! Antivirus
Downloader.Agent.Win32.186880
2.0.0.1936

File size:
237.3 KB (242,984 bytes)

Product version:
2.4.8.1

Copyright:
Copyright (C) 2013 Premium Installer

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Language:
English (United States)

Common path:
C:\users\{user}\downloads\torrent.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/3/2013 8:00:00 PM

Valid to:
9/20/2014 7:59:59 PM

Subject:
CN=WARP INSTALLER, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=WARP INSTALLER, L=Kansas City, S=Missouri, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2073183E3CAF3D7A109497C973C378FF

File PE Metadata
Compilation timestamp:
5/7/2014 9:31:12 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:5mRBZ5FW5sXB9pkTiCLGFEqfi7tRmfjNrQ/Jig426VT5txp/aU:54B1CgBHkNLoTyR+jNPxp/aU

Entry address:
0xE682

Entry point:
E8, 85, 65, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 80, C2, 42, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 3C, C0, 42, 00, C9, C2, 08, 00, 8B, FF, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64, 8B, 1D, 00, 00, 00, 00, 8B, 03, 64, A3, 00, 00, 00, 00, 8B, 45, 08, 8B, 5D, 0C, 8B, 6D, FC, 8B, 63...
 
[+]

Entropy:
6.3882

Code size:
171 KB (175,104 bytes)

The file torrent.exe has been seen being distributed by the following URL.

Remove torrent.exe - Powered by Reason Core Security