uTorrent.exe

µTorrent

BitTorrent Inc

µTorrent is a free ad-supported lightweight BitTorrent client. This is a setup program which is used to install the application. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘uTorrent’. This is installed with µTorrent. The file has been seen being downloaded from ftp-stahuj.centrum.cz and multiple other hosts.
Publisher:
BitTorrent Inc.  (signed by BitTorrent Inc)

Product:
µTorrent

Version:
3.3.0.29677

MD5:
ad039bd721859550f23064d42e7dda44

SHA-1:
d2408c8a09a2bd9704af39f818ec7ac9e9cca46e

SHA-256:
918812f078d796adfe12a67ca802e9da9d5fd48629a69e479009b9babc099175

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 5:23:27 AM UTC  (today)

File size:
1020.6 KB (1,045,072 bytes)

Product version:
3.3.0.29677

Copyright:
©2012 BitTorrent, Inc. All Rights Reserved.

Original file name:
uTorrent.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\utorrent\utorrent.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/21/2010 2:00:00 AM

Valid to:
7/27/2013 1:59:59 AM

Subject:
CN=BitTorrent Inc, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=BitTorrent Inc, L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
36BC30562A650AFAA5AD101ECD643AB4

File PE Metadata
Compilation timestamp:
5/11/2013 12:10:34 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:eqWTs+rr/AXxMd7j2JZZj1U6v2tuDwryDDz+1dqep+:eqWtv7j2JZZ1vlDgfqep+

Entry address:
0x243360

Entry point:
60, BE, 00, D0, 58, 00, 8D, BE, 00, 40, E7, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, 34, 16, 24, 00, 57, 83, C3, 04, 53, 68, 5A, 63, 0B, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Code size:
732 KB (749,568 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
uTorrent

Command:
C:\users\{user}\appdata\roaming\utorrent\utorrent.exe \minimized


2 Windows Firewall Allowed Programs
Name:
C:\Program Files\uTorrent.exe

Name:
C:\Documents and Settings\KJ\Asztal\utorrent.exe


The file uTorrent.exe has been discovered within the following programs.

µTorrent  by BitTorrent Inc.
µTorrent is a is a free, ad-supported, lighter-weight BitTorrent client designed to consume less resources then the full BitTorrent version.
www.utorrent.com
12% remove it
ArtRage 2  by Ambient Design
Publisher's description - “ArtRage is a stylish, intuitive painting and drawing package that makes it easy to produce natural looking artwork on your computer. Because ArtRage is designed to work like real painting and drawing tools, it can be used by almost anyone.”
www.artrage.com/artrage.html
About 7% of users remove it
Borderlands  by 2K Games
Borderlands is an action role-playing first-person shooter video game, that was developed by Gearbox Software. Borderlands includes character-building elements found in role-playing games, leading Gearbox to call the game a "role-playing shooter".
www.borderlandsthegame.com
5% remove it
uTorrentControl_v6 Toolbar  by Conduit Ltd.
uTorrent Control v6 Toolbar is a 'Community Toolbar' from Conduit, which integrates with major web browsers including Google Chrome, Firefox and Internet Explorer.
uTorrentControlv6.OurToolbar.com
82% remove it
Publisher's description - “The Xirrus Wi-Fi Inspector is a powerful tool for managing and troubleshooting the Wi-Fi on a Windows XP SP2 or later, Vista, or 7 laptop. Built in tests enable you to characterize the integrity and performance of your Wi-Fi connection. ”
www.xirrus.com
9% remove it
 
Powered by Should I Remove It?

The file uTorrent.exe has been seen being distributed by the following 42 URLs.

http://ftp-stahuj.centrum.cz/dl/60ed770c62edcaefc3918c487e99af0c/51d485fe/stahuj/download/software/secured/u/utorrent/330/.../utorrent.exe

http://download846.mediafire.com/89ou8qjint9g/.../utorrent_2.exe

http://dl1.filesoul.com/.../uTorrent-3-3-Build-29677.exe

http://download846.mediafire.com/nzrxn52j05wg/.../utorrent.exe

https://dw.uptodown.com/dwn/Qg4mA4YWZ4FfZxqS-4gvu2p2YDeEpfl6iMw3jjQpjih4kiaPpkrpfqXLeF2R54-1X5GTKoKTe4FVmX7gHVTLFah9Nj7RZhWYIX-X3XSWBhuR4bAuLiT-76Uir1IIIA7z/x38TCzOBI0Uz_HpNzsg2G9F1QYI2p2gIfWtFGxxPUWqS6Stg8TDR3tnI2DCID9TjIglIyxpsKPcFFnaZABT6MRysNoph5bvjG0dErebieKapo616ARlndykMTfMZmCYZ/Mx4dClldeaVZdi3GO_ig16H8N2QDt1E9dpoE4iIBJrjeejC5pGuUHq4Gv-6if4Lnr66fnBrQX19ajWbFiv_tT8pVnekqA9RIb1LR_pEa3XLsR1d_T-GCY6RQ8A_Mf1ug/.../

https://mega.nz/persistent/.../IR4zmJLT

https://mega.nz/temporary/.../IR4zmJLT

Latest 30 of 42 download URLs

Scan uTorrent.exe - Powered by Reason Core Security