Should I block it?
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization
Additional versions
Relationships
uTorrent.exe
µTorrent by BitTorrent Inc (Signed)
Version: | 3.3.0.29677 |
MD5: | 346736ef043c6920a9d64cbe63cf9b64 |
SHA1: | dfc84d0e9d2e4190b7a72d283170c58312fe5d11 |
SHA256: | fa4aacd5863d992bdd77be8d41d157dd35ad544262117afdb32a4ab895654e5a |
Warning 5 antivirus scanners has detected malware.
Overview
utorrent.exe is malware that executes as a process with the local user's privileges. It is set to be run when the PC boots and the user logs into Windows (added to the Run registry key for the current user). It has been configured with a firewall exception which allows both inbound and outbound network communication without being blocked. It is installed with a couple of know programs including µTorrent published by BitTorrent Inc., µTorrent from BitTorrent Inc. and µTorrent by BitTorrent Inc..
Details
File name: | utorrent.exe |
Publisher: | BitTorrent Inc. |
Product name: | µTorrent |
Typical file path: | C:\Program Files\utorrent\utorrent.exe |
File version: | 3.3.0.29677 |
Size: | 1020.58 KB (1,045,072 bytes) |
Build date: | 5/11/2013 1:10 AM |
Certificate |
Issued to: | BitTorrent Inc |
Authority (CA): | VeriSign |
Effective date: | Monday, June 21, 2010 |
Expiration date: | Saturday, July 27, 2013 |
Digital DNA |
PE subsystem: | Windows GUI |
File packed: | Yes |
Code language: | Microsoft Visual C++ |
.NET CLR: | No |
More details
Programs
The following programs will install this file
µTorrent is a is a free, ad-supported, lighter-weight BitTorrent client designed to consume less resources then the full BitTorrent version. Some uTorrent installs include potentially unwanted programs in the form of the Conduit Engine, which installs a toolbar, and makes homepage and default search engine changes to a user's web browser.
VLC media player (also known as VLC) is a highly portable free and open-source cross-platform media player and streaming media server written by the VideoLAN project. VLC media player supports many audio and video compression methods and file formats, including DVD-video, video CD and streaming protocols. It is able to stream over computer network and to transcode multimedia files. The default distribution of VLC includes a large number...
Behaviors
Windows firewall allowed programs
Exceptions allow programs to access to the Internet through an outbound connections
- Firewall exception for 'C:\Documents and Settings\user\Application Data\uTorrent\uTorrent.exe'
- Firewall exception for 'C:\Documents and Settings\user\Application Data\uTorrent\uTorrent.exe'
- Firewall exception for 'C:\Documents and Settings\user\Application Data\uTorrent\uTorrent.exe'
- Firewall exception for 'C:\Documents and Settings\user\Application Data\uTorrent\uTorrent.exe'
- Firewall exception for 'C:\Program Files\uTorrent\uTorrent.exe'
- Firewall exception for 'C:\Program\uTorrent\uTorrent.exe'
- Firewall exception for 'C:\Documents and Settings\user\Application Data\uTorrent\uTorrent.exe'
- Firewall exception for 'C:\Documents and Settings\user\Application Data\uTorrent\uTorrent.exe'
- Firewall exception for 'C:\Documents and Settings\user\Application Data\uTorrent\uTorrent.exe'
- Firewall exception for 'C:\Program Files\uTorrent\uTorrent.exe'
- Firewall exception for 'C:\Documents and Settings\user\Application Data\uTorrent\uTorrent.exe'
- Firewall exception for 'C:\Documents and Settings\user\Application Data\uTorrent\uTorrent.exe'
- Firewall exception for 'C:\Program Files\uTorrent\uTorrent.exe'
Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
- 'uTorrent' → "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED
Network connections
Access through an approved Windows firewall exception
[TCP] port-8-adslby-pool39.infonet.by (81.25.39.8:54964)
[UDP] listens on port 1080
Malware detections
Based on 40+ industry antivirus scanners, 5 of them detected the following malware.
Antivirus engine | Engine version | Detection |
Comodo Internet Security |
16911 |
UnclassifiedMalware |
ESET NOD32 |
7.8781 |
a variant of Win32/Bunndle |
Fortinet |
5.1.147.0 |
W32/Bunndle |
McAfee |
5.600.1067 |
RDN/Generic BackDoor!ps |
McAfee Gateway Anti-Malware |
v2013-dat |
RDN/Generic BackDoor!ps |
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
CPU |
Total CPU: | 0.00119455% | |
Kernel CPU: | 0.00017803% | |
User CPU: | 0.00101651% | |
Kernel CPU time: | 129,109,375 ms/min | |
Context switches: | 96/sec | |
Memory |
Private memory: | 40.09 MB | |
Private (maximum): | 50.42 MB | |
Private (minimum): | 4.96 MB | |
Non-paged memory: | 40.09 MB | |
Virtual memory: | 300.92 MB | |
Virtual memory (peak): | 329.98 MB | |
Working set: | 14.91 MB | |
Working set (peak): | 52.77 MB | |
Resource allocations |
Threads: | 46 | |
Handles: | 627 | |
GUI GDI count: | 230 | |
GUI USER count: | 130 | |
Process properties
Tray notification: | Yes |
Integrety level: | Undefined |
Platform: | 32-bit |
Command line: | "C:\documents and settings\micki muys\??? ?????????\????????\utorrent.exe" /minimized |
Owner: | User |
Distribution by Windows OS
OS version | distribution |
Windows 7 Home Premium |
22.34% |
|
Windows 7 Ultimate |
19.80% |
|
Microsoft Windows XP |
19.80% |
|
Windows 8 Pro |
7.11% |
|
Windows 8.1 |
6.09% |
|
Windows 8 |
5.08% |
|
Windows 8.1 Pro |
4.06% |
|
Windows 7 Professional |
3.05% |
|
Windows 7 Home Basic |
2.54% |
|
Windows 8.1 Single Language |
2.03% |
|
Windows 8 Single Language |
2.03% |
|
Windows 8 Pro with Media Center |
2.03% |
|
Windows Vista Home Premium |
1.02% |
|
Windows 7 Starter |
1.02% |
|
Windows 8.1 N |
0.51% |
|
Windows 8.1 Pro with Media Center |
0.51% |
|
Windows Developer Preview |
0.51% |
|
Windows 8 Enterprise Evaluation |
0.51% |
|
Distribution by country
United States installs about 25.89% of µTorrent.
Distribution by PC manufacturer
PC Manufacturer | distribution |
Dell |
20.81% |
|
Hewlett-Packard |
17.65% |
|
ASUS |
15.38% |
|
Toshiba |
8.14% |
|
Lenovo |
7.24% |
|
Acer |
6.79% |
|
Sony |
5.43% |
|
GIGABYTE |
4.52% |
|
American Megatrends |
4.07% |
|
Intel |
3.62% |
|
Samsung |
2.71% |
|
MSI |
1.81% |
|
Alienware |
1.36% |
|
Packard Bell |
0.45% |
|