Should I block it?

60%
60% of PCs block this file from running.
Possible reason:
Performance resource utilization

VersionsAdditional versions

25.0 6.67%
25.0 8.89%
25.0 13.33%
25.0 8.89%
25.0 11.11%
25.0 11.11%
0.0 8.89%
0.0 20.00%
0.0 4.44%
0.0 2.22%
0.0 2.22%
0.0 2.22%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
CheckTokenMembership, FreeSid, OpenProcessToken, DuplicateTokenEx, ImpersonateLoggedOnUser, QueryServiceObjectSecurity, GetSecurityDescriptorDacl, BuildExplicitAccessWithNameW, SetEntriesInAclW, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, SetServiceObjectSecurity, ControlService, DeleteService, CreateServiceW, ChangeServiceConfig2W, StartServiceW, QueryServiceStatus, OpenSCManagerW, OpenServiceW, ChangeServiceConfigW, CloseServiceHandle, StartServiceCtrlDispatcherW, RegisterServiceCtrlHandlerW, RegisterEventSourceW, ReportEventW, DeregisterEventSource, SetServiceStatus, RevertToSelf, CreateProcessAsUserW, LookupPrivilegeValueW, AdjustTokenPrivileges, ConvertSidToStringSidW, GetTokenInformation, GetLengthSid, CopySid, RegQueryValueExW, RegEnumKeyExW, RegCloseKey, AllocateAndInitializeSid, RegOpenKeyExW
dbghelp.dll
SymInitialize, SymCleanup, SymGetLineFromAddr, UnDecorateSymbolName, SymGetSymFromAddr64, SymGetModuleBase, SymFunctionTableAccess, StackWalk, SymSetOptions
kernel32.dll
WriteConsoleW, FreeLibrary, LoadLibraryW, SetConsoleCtrlHandler, IsValidLocale, SetStdHandle, SetEndOfFile, CompareStringW, SetEnvironmentVariableA, GetCurrentProcess, GetProcessHeap, HeapAlloc, LocalFree, HeapFree, GetModuleFileNameW, GetTempPathW, MoveFileW, DeleteFileW, CreateEventW, WaitForSingleObject, GetSystemTimeAsFileTime, CreateDirectoryW, CreateFileW, WriteFile, QueueUserWorkItem, GetLastError, InterlockedDecrement, OpenEventW, SetEvent, CloseHandle, Sleep, GetModuleHandleW, GetProcAddress, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, GetDriveTypeW, InitializeCriticalSection, EnumSystemLocalesA, GetLocaleInfoA, GetUserDefaultLCID, HeapReAlloc, HeapQueryInformation, SetCurrentDirectoryW, GetCurrentDirectoryW, CreateFileA, PeekNamedPipe, GetFileInformationByHandle, GetFullPathNameA, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, GetEnvironmentStringsW, FreeEnvironmentStringsW, SetFilePointer, GetConsoleMode, GetConsoleCP, FatalAppExitA, lstrlenW, SetUnhandledExceptionFilter, CopyFileA, GetCurrentThread, RtlCaptureContext, FormatMessageA, GetCurrentDirectoryA, GetModuleFileNameA, WTSGetActiveConsoleSessionId, OpenProcess, Process32NextW, ProcessIdToSessionId, Process32FirstW, CreateToolhelp32Snapshot, CreateProcessW, MultiByteToWideChar, WideCharToMultiByte, CreateNamedPipeW, LocalAlloc, DisconnectNamedPipe, FlushFileBuffers, TerminateThread, ConnectNamedPipe, CreateThread, GetFileAttributesW, IsWow64Process, GetVersionExW, GetLocaleInfoW, ReadFile, GetFileSize, WaitNamedPipeW, InterlockedIncrement, GetStringTypeW, InterlockedCompareExchange, InterlockedExchange, EncodePointer, DecodePointer, RtlUnwind, RaiseException, GetCommandLineW, HeapSetInformation, FindClose, FileTimeToSystemTime, FileTimeToLocalFileTime, GetDriveTypeA, FindFirstFileExA, GetTimeFormatA, GetDateFormatA, LCMapStringW, GetCPInfo, IsProcessorFeaturePresent, UnhandledExceptionFilter, IsDebuggerPresent, TerminateProcess, GetTimeZoneInformation, GetStdHandle, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, SetLastError, GetCurrentThreadId, HeapCreate, HeapDestroy, HeapSize, ExitProcess, GetACP, GetOEMCP, IsValidCodePage, SetHandleCount, InitializeCriticalSectionAndSpinCount, GetFileType, GetStartupInfoW, lstrlenA
ole32.dll
CLSIDFromProgID, CoCreateGuid, CoUninitialize, CoInitialize, CoCreateInstance
psapi.dll
GetProcessMemoryInfo
rpcrt4.dll
RpcStringFreeW, UuidToStringW
shell32.dll
SHGetFolderPathW
shlwapi.dll
PathFindFileNameW, UrlEscapeW, PathFileExistsW
user32.dll
wsprintfW
userenv.dll
CreateEnvironmentBlock, DestroyEnvironmentBlock
wtsapi32.dll
WTSQueryUserToken

TorchCrashHandler.exe

TorchCrashHandler by Torch Media Inc. (Signed)

Remove TorchCrashHandler.exe
Version:   0.0
MD5:   e21be2f36d6a87d3ba8e5e80eeb8ddc9
SHA1:   3e2f637b08163c6df76dba728a373bca9314a096
SHA256:   73c2201e75fd42bbe2587c9a263cb11d742f5e01a183742a8513604d4ddee352

Overview

torchcrashhandler.exe runs as a service under the name TorchCrashHandler (TorchCrashHandler) with extensive SYSTEM privileges (full administrator access). The file is digitally signed by Torch Media Inc. which was issued by the Thawte certificate authority (CA).

DetailsDetails

File name:torchcrashhandler.exe
Publisher:TorchMedia Inc.
Product name:TorchCrashHandler
Typical file path:C:\users\user\appdata\local\torch\update\torchcrashhandler.exe
File version:0.0
Product version:0.0.0.1049
Size:1.16 MB (1,213,280 bytes)
Build date:10/7/2013 8:46 AM
Certificate
Issued to:Torch Media Inc.
Authority (CA):Thawte
Digital DNA
PE subsystem:Windows Console
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • TorchCrashHandler
  • 'TorchCrashHandler' (Torch Crash Handler)

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00223671%
0.028634%
Kernel CPU:0.00222773%
0.013761%
User CPU:0.00000898%
0.014873%
Kernel CPU time:78,016 ms/min
100,923,805ms/min
Memory
Private memory:3.61 MB
21.59 MB
Private (maximum):8.19 MB
Private (minimum):7.84 MB
Non-paged memory:3.61 MB
21.59 MB
Virtual memory:118.73 MB
140.96 MB
Virtual memory (peak):168.04 MB
169.69 MB
Working set:7.85 MB
18.61 MB
Working set (peak):8.23 MB
37.95 MB
Resource allocations
Threads:6
12
Handles:131
600

BehaviorsProcess properties

Integrety level:System
Platform:64-bit
Command line:C:\users\user\appdata\local\torch\update\torchcrashhandler.exe
Owner:SYSTEM
Windows Service
Service name:TorchCrashHandler
Display name:TorchCrashHandler
Description:“The crash handler service automatically updates Torch to the latest version and sends anonymous crash reports when Torch unexpectedly shuts down, to ensure that Torch offers the best performance and security.”
Type:Win32OwnProcess, InteractiveProcess
Parent process:services.exe (Services and Controller app by Microsoft)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 39.53%
Windows 7 Home Premium 30.23%
Microsoft Windows XP 6.98%
Windows 8 Pro 6.98%
Windows 8.1 Pro 2.33%
Windows 8.1 Enterprise 2.33%
Windows 8.1 Single Language 2.33%
Windows 8 2.33%
Windows 8 Enterprise 2.33%
Windows Seven Black Edition 2.33%
Windows 7 Professional 2.33%

Distribution by countryDistribution by country

United States installs about 19.51% of TorchCrashHandler.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
ASUS 23.73%
Acer 22.03%
Dell 20.34%
Hewlett-Packard 15.25%
Lenovo 3.39%
Compaq 3.39%
Sony 3.39%
Intel 3.39%
Toshiba 3.39%
GIGABYTE 1.69%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE