TornTV Hijacker

TornTV Hijacker Description

TornTV Hijacker Image 1The TornTV Hijacker is a threat that is associated with Torn TV, an online service that supposedly allows computer users to watch TV shows on their computer, both in live streams and by downloading videos of the episodes the user wants to watch. It is possible to install Torn TV directly from the company's website. Security researchers have observed that criminals bundle this application with malicious toolbars and adware, such as CouponDropDown. This added malware will often be installed by default unless the computer user opts out. However, the installer is designed to make the opt-out check boxes easy to miss. It is also important to point out that Torn TV and the TornTV Hijacker are built on Yontoo, a platform that has been closely associated with adware and irritating browser hijackers. ESG security researchers consider that the TornTV Hijacker poses as a security risk.

The TornTV Hijacker May Be Associated with the Bifrose Backdoor Trojan

One of the reasons why ESG security researchers consider the TornTV Hijacker more dangerous than typical adware hijackers is that there have been reports of the TornTV Hijacker being installed along with the Bifrose backdoor Trojan. This is a dangerous malware infection that creates an unauthorized opening in the infected computer's security. This allows criminals to gain access to the infected computer from a remote location, allowing them to spy on your online activity and install other malware on your computer.

The main symptom associated with TornTV Hijacker is the way TornTV Hijacker affects its victim's web browsing. The TornTV Hijacker takes over the victim's web browser, forcing it to visit the Torn TV website repeatedly. The victim's homepage, default search engine, favorite websites and other predetermined websites may also be changed by the TornTV Hijacker without the computer user's authorization. Since the TornTV Hijacker makes unwanted changes to your web browser's settings, removing TornTV Hijacker involves undoing these unwanted changes as well. ESG security researchers advise using a reliable anti-malware program to remove the TornTV Hijacker from your computer and then making sure that all of your security settings and web browser preferences had been restored to what they were before the computer was infected with the TornTV Hijacker.

Technical Information

File System Details

TornTV Hijacker creates the following file(s):
# File Name Size MD5 Detection Count
1 %APPDATA%QN.exe 1,536,920 0824d234bfda0d990f0619a5f320094b 97
2 %APPDATA%WUGSIR.exe 1,989,016 59cea2dc95497b2c6c602c55b0ccc7f0 88
3 %APPDATA%WEUXZL.exe 1,514,904 1e61ff6b229752abc3452d0b2deda56e 52
4 %APPDATA%\TornTV.com\Torntv.exe 827,584 2942e7c6bda7788e4f5c8abb9c670459 47
5 %APPDATA%\TornTV.com\TornTVSvc.exe 10,240 a6d7e56256341edbcf10fb780837b946 33
6 %PROGRAMFILES%\TheTorntv V10\d9503c84-2293-468d-8eb7-12ba4f5c7b46-4.exe 866,216 43b539782361506c7cbb6056a50f7730 6
7 %PROGRAMFILES%\TheTorntv V10\330a8f7f-1bb3-4d1e-8fc4-f534bf97ef74-11.exe 1,913,256 1d882bd07c9a0fdd0442a1c331650c35 3
8 %PROGRAMFILES%\TheTorntv V10\TheTorntv V10-bho.dll 618,920 2daa2e195db8bc7b02ee22578e45890e 3
9 %USERPROFILE%\Start Menu\Programs\Startup\TorntvDownloader.lnk 1,930 178b840632d0382d2e315091a0b87d51 3
10 %APPDATA%\TornTV.com\TornTV Downloader.exe 310,272 ffccd2cc44aac7a7ea2aabab325cc3ed 3
11 %PROGRAMFILES%\TheTorntv V10\3591f84d-d448-49ac-89c2-bf96a9734b03-11.exe 1,886,632 b32f2bbf23bdfc88442f77bb250592e7 2
12 %PROGRAMFILES%\TheTorntv V10\3591f84d-d448-49ac-89c2-bf96a9734b03-4.exe 824,232 f419a1d9a7b4fca01e820c7437db7127 2
13 %PROGRAMFILES(x86)%\TheTorntv V10\2aa1772a-2c85-4293-91e4-48d808a6d9cf-11.exe 1,977,768 c7d988577be492bf1a124cdb21156ba2 2
14 %PROGRAMFILES(x86)%\TheTorntv V10\2aa1772a-2c85-4293-91e4-48d808a6d9cf-4.exe 904,616 c7d637afffbb6f4729d5e5225ed3fe29 2
15 %PROGRAMFILES%\TheTorntv V10\92a411f9-bdce-4676-b566-af6550048374-4.exe 834,472 85840f69b79452d977884718ef4bd867 2
16 %PROGRAMFILES%\TheTorntv V10\92a411f9-bdce-4676-b566-af6550048374-3.exe 1,901,992 5fe48d8ab184afb406be7b79c40e1582 2
17 %PROGRAMFILES%\TheTorntv V10\3273c73f-99bb-470d-94fd-24a02ec3aa15-11.exe 1,960,872 c672d9b2719b1b85ba273c3731a768e9 2
18 %PROGRAMFILES%\TheTorntv V10\3273c73f-99bb-470d-94fd-24a02ec3aa15-4.exe 887,720 6d36e0406ac8c92311e60254ec8ed9f6 2
19 %APPDATA%\TornTV.com\TornTvUpdater.exe 9,216 a5c1e41bd1982666e3fc61cd60cde5f0 2
20 %PROGRAMFILES(x86)%\TheTorntv V10\TheTorntv V10-bho64.dll 910,248 a5e2bea8137bb6fde2bc767c9ba2cbd6 1
21 %PROGRAMFILES%\TheTorntv V10\004d8d5b-1779-4352-ba15-f9ee38bb42da-3.exe 1,904,040 ffe6a2cf312f084c30ef744e52651806 1
22 %PROGRAMFILES%\TheTorntv V10\2f2c7e6e-db6a-40a8-970e-6cb44137e9ac-11.exe 1,903,016 bb1f79fae31188f95a9357519864a082 1
23 %PROGRAMFILES%\TheTorntv V10\2f2c7e6e-db6a-40a8-970e-6cb44137e9ac-4.exe 838,568 44d1102b6c3dcf3eaf9d0a4933161907 1
24 %PROGRAMFILES%\TheTorntv V10\1d47d9cb-6231-4d32-abdf-dcfb883b99eb-11.exe 1,884,072 ddc1a3e34ad917b45e586dbef46946bf 1
25 TornUpdatePack.exe 649,336 e357d85de7c2d00bef446f449c3834e9 1
26 %APPDATA%\TornTV.com\log\torntvupdater10.exe 231,768 df028f7a84c202280ed205c3e3933909 1
27 torntv.exe N/A
28 server.exe N/A
29 %ProgramFiles%\YontooIEClient.DLL N/A
30 %ProgramFiles%\TornTV.com\* N/A
More files

Registry Details

TornTV Hijacker creates the following registry entry or registry entries:
Uninstaller
1ClickDownload
1ClickDownloader
Torntv V7.0
Torntv V9.0
Registry key
Software\1ClickDownload
Software\AppDataLow\Software\Crossrider\onBeforeNavigate\35578
Software\AppDataLow\Software\Crossrider\onBeforeNavigate\45960
Software\AppDataLow\Software\Crossrider\onBeforeNavigate\49040
Software\AppDataLow\Software\Crossrider\onBeforeNavigate\51390
Software\AppDataLow\Software\Crossrider\onRequest\35578
Software\AppDataLow\Software\Crossrider\onRequest\45960
Software\AppDataLow\Software\Crossrider\onRequest\49040
Software\AppDataLow\Software\Crossrider\onRequest\51390
Software\AppDataLow\Software\Torntv 2
Software\AppDataLow\Software\Torntv V6.0
Software\AppDataLow\Software\Torntv V7.0
Software\AppDataLow\Software\Torntv V9.0
Software\AppDataLow\Software\V9.0 Torntv 1.1
SOFTWARE\Classes\.torrent\OpenWithProgIDs\TorntvDownloader
SOFTWARE\Classes\6bd34e315cba4997ad71181b65e074a50070001.BHO
SOFTWARE\Classes\6bd34e315cba4997ad71181b65e074a50070001.BHO.1
SOFTWARE\Classes\6bd34e315cba4997ad71181b65e074a50070001.Sandbox
SOFTWARE\Classes\6bd34e315cba4997ad71181b65e074a50070001.Sandbox.1
SOFTWARE\Classes\9ab333d0052b01323ffd0f6cdde3bdb00063311.BHO
SOFTWARE\Classes\9ab333d0052b01323ffd0f6cdde3bdb00063311.BHO.1
SOFTWARE\Classes\9ab333d0052b01323ffd0f6cdde3bdb00063311.Sandbox
SOFTWARE\Classes\9ab333d0052b01323ffd0f6cdde3bdb00063311.Sandbox.1
SOFTWARE\Classes\CrossriderApp0035578.BHO
SOFTWARE\Classes\CrossriderApp0035578.BHO.1
SOFTWARE\Classes\CrossriderApp0035578.Sandbox
SOFTWARE\Classes\CrossriderApp0045960.BHO
SOFTWARE\Classes\CrossriderApp0045960.BHO.1
SOFTWARE\Classes\CrossriderApp0045960.Sandbox
SOFTWARE\Classes\CrossriderApp0045960.Sandbox.1
SOFTWARE\Classes\CrossriderApp0049040.BHO
SOFTWARE\Classes\CrossriderApp0049040.BHO.1
SOFTWARE\Classes\CrossriderApp0049040.Sandbox
SOFTWARE\Classes\CrossriderApp0049040.Sandbox.1
SOFTWARE\Classes\CrossriderApp0051390.BHO
SOFTWARE\Classes\CrossriderApp0051390.BHO.1
SOFTWARE\Classes\CrossriderApp0051390.Sandbox
SOFTWARE\Classes\CrossriderApp0051390.Sandbox.1
Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\TheTorntv V10
Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Torntv 2
Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Torntv V6.0
Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Torntv V7.0
Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Torntv V9.0
Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\V9.0 Torntv 1.1
SOFTWARE\Classes\TorntvDownloader
Software\Classes\TornTvDownloader.File
Software\Classes\TornTvDownloader.File\
SOFTWARE\Classes\TorntvDownloader.torrentFile
Software\Crossrider\onBeforeNavigate\51390
Software\Crossrider\onRequest\51390
SOFTWARE\Google\Chrome\Extensions\jbpkiefagocgkmemidfngdkamloieekf
SOFTWARE\Google\Chrome\Extensions\jplinpmadfkdgipabgcdchbdikologlh
SOFTWARE\Google\Chrome\Extensions\nbmafkdmkkckhggblphicnnhlgljnoje
Software\InstalledBrowserExtensions\3874
Software\InstalledBrowserExtensions\esc\61177
Software\InstalledBrowserExtensions\esc\61855
Software\InstalledBrowserExtensions\esc\63311
Software\InstalledBrowserExtensions\Qwerty
Software\InstalledBrowserExtensions\tom\51390
Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110311551178}
Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110411591160}
Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110411901140}
Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110511131190}
Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration\{11111111-1111-1111-1111-110311551178}
Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration\{11111111-1111-1111-1111-110411591160}
Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration\{11111111-1111-1111-1111-110411901140}
Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration\{11111111-1111-1111-1111-110511131190}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{03a7f11c-9738-4147-aa95-53f19f7acaf6}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{046b5803-0809-4af4-86d1-49a8a6e3e77e}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{091f7430-e568-4477-8302-60be90dff142}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0eac069f-41c7-4df5-8143-3808234c9e15}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21d81749-b73c-4ada-a1e9-f3c79779a743}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4391e1a3-6881-425b-8f13-e1d11b4e4cda}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{44141d66-1fa6-4c28-b2d9-07fd14352eb6}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{547e32d9-d44c-4e27-8eb1-38139385cb1b}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5c17b20f-6076-4378-9abe-687ace5b2ee5}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5cfad20e-6920-4da6-8014-cb1a1347d497}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{698052cc-e3ca-48c9-ae68-6d5d5934797c}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70fc0ad7-e6e0-4273-8d17-63b240e194b2}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7d7b90ec-0f77-49ec-bfa5-07a12bb9f394}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7e8b9605-0386-4d5b-973f-06444721f450}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{84014d04-125a-4cb6-99a8-dc29ee36459f}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{844df3e1-690e-4fee-b263-3c437e27d628}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8f3263a9-ae07-449d-bf03-5cedf0e9d7ae}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9518bc89-9639-4183-804d-7af98b230886}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9bb72b76-56f5-40bc-bcfe-583aa8efa8d1}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9ce037a0-9f4d-4d58-82be-ce45256d47da}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ab3b6b05-5dfc-4ebd-a023-2bde2ef48487}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ac675dc0-4e83-4f1e-a6aa-2fadf678459f}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{bc8988c0-651c-4ae6-a307-1ab9e2da67b9}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{c002c2b0-b030-4fb9-898f-66aa04ed7768}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ccffe97f-6737-43a1-a9f9-4a0c78082e0b}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d49cfa8c-0142-453f-bc43-12931743833d}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d59e146b-1f74-453f-8244-899e65b3d975}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d8440e5c-16c7-4ada-855f-d069c4a64673}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{df1ddecd-5fe5-4e0c-872b-ae4985af5171}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e25bd778-2418-43bd-b417-98d94f67b0ed}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ecbe83d0-245c-4197-accb-06a3724d15d5}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f585a701-a226-4877-9017-837f3e37a228}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fa83ca79-53ef-4d9d-b3a0-8724dc94fbae}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{febbade8-04ef-47cd-9766-290e82ccfe52}
SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\TheTorntvs V10 1.1 --bg.exe
SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Torntv V6.0-bg.exe
SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Torntv V7.0-bg.exe
SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Torntv V9.0-bg.exe
SOFTWARE\Microsoft\Tracing\Torntv Downloader_RASAPI32
SOFTWARE\Microsoft\Tracing\Torntv Downloader_RASMANCS
SOFTWARE\Microsoft\Tracing\TornTVSetup_RASAPI32
SOFTWARE\Microsoft\Tracing\TornTVSetup_RASMANCS
SOFTWARE\Microsoft\Tracing\TornTVSvc_RASAPI32
SOFTWARE\Microsoft\Tracing\TornTVSvc_RASMANCS
SOFTWARE\Microsoft\Tracing\TornTvUpdater_RASAPI32
SOFTWARE\Microsoft\Tracing\TornTvUpdater_RASMANCS
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Torntv V6.0-firefoxinstaller.job
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Torntv V6.0-firefoxinstaller.job.fp
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Torntv V6.0-updater.job
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Torntv V6.0-updater.job.fp
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Torntv V6.0-chromeinstaller
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311551178}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411901140}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511131190}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110311551178}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110411591160}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110511131190}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110311551178}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110411591160}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110411901140}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110511131190}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110311551178}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411591160}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411901140}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110511131190}
Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{11111111-1111-1111-1111-110311551178}
Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{11111111-1111-1111-1111-110411591160}
SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{11111111-1111-1111-1111-110511131190}
SOFTWARE\Microsoft\Windows\CurrentVersion\Run\TornTv Downloader
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Torntv V6.0
Software\TheTorntvs V10 1.1 -
Software\TornTv Downloader
SOFTWARE\Torntv V6.0
SOFTWARE\Torntv V7.0
SOFTWARE\Torntv V9.0
SOFTWARE\Wow6432Node\Google\Chrome\Extensions\bicnnkjibmphdeigoodpjlcklcnaobdj
SOFTWARE\Wow6432Node\Google\chrome\Extensions\jbpkiefagocgkmemidfngdkamloieekf
SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jplinpmadfkdgipabgcdchbdikologlh
SOFTWARE\Wow6432Node\Google\Chrome\Extensions\nbmafkdmkkckhggblphicnnhlgljnoje
SOFTWARE\Wow6432Node\InstalledBrowserExtensions\3874
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{03a7f11c-9738-4147-aa95-53f19f7acaf6}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{046b5803-0809-4af4-86d1-49a8a6e3e77e}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{091f7430-e568-4477-8302-60be90dff142}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0eac069f-41c7-4df5-8143-3808234c9e15}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21d81749-b73c-4ada-a1e9-f3c79779a743}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4391e1a3-6881-425b-8f13-e1d11b4e4cda}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{44141d66-1fa6-4c28-b2d9-07fd14352eb6}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{547e32d9-d44c-4e27-8eb1-38139385cb1b}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5c17b20f-6076-4378-9abe-687ace5b2ee5}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5cfad20e-6920-4da6-8014-cb1a1347d497}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{698052cc-e3ca-48c9-ae68-6d5d5934797c}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70fc0ad7-e6e0-4273-8d17-63b240e194b2}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7d7b90ec-0f77-49ec-bfa5-07a12bb9f394}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7e8b9605-0386-4d5b-973f-06444721f450}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{84014d04-125a-4cb6-99a8-dc29ee36459f}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{844df3e1-690e-4fee-b263-3c437e27d628}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8f3263a9-ae07-449d-bf03-5cedf0e9d7ae}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9518bc89-9639-4183-804d-7af98b230886}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9bb72b76-56f5-40bc-bcfe-583aa8efa8d1}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9ce037a0-9f4d-4d58-82be-ce45256d47da}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ab3b6b05-5dfc-4ebd-a023-2bde2ef48487}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{bc8988c0-651c-4ae6-a307-1ab9e2da67b9}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{c002c2b0-b030-4fb9-898f-66aa04ed7768}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ccffe97f-6737-43a1-a9f9-4a0c78082e0b}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d49cfa8c-0142-453f-bc43-12931743833d}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d59e146b-1f74-453f-8244-899e65b3d975}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d8440e5c-16c7-4ada-855f-d069c4a64673}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{df1ddecd-5fe5-4e0c-872b-ae4985af5171}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e25bd778-2418-43bd-b417-98d94f67b0ed}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ecbe83d0-245c-4197-accb-06a3724d15d5}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f585a701-a226-4877-9017-837f3e37a228}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fa83ca79-53ef-4d9d-b3a0-8724dc94fbae}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{febbade8-04ef-47cd-9766-290e82ccfe52}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Torntv 2-bg.exe
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Torntv V6.0-bg.exe
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Torntv V7.0-bg.exe
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Torntv V9.0-bg.exe
SOFTWARE\Wow6432Node\Microsoft\Tracing\Torntv Downloader_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\Torntv Downloader_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Tracing\TornTV_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\TornTV_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311551178}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411901140}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511131190}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110311551178}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110411591160}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110411901140}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110511131190}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{11111111-1111-1111-1111-110511131190}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Torntv 2
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Torntv V6.0
SOFTWARE\Wow6432Node\Torntv 2
SOFTWARE\Wow6432Node\Torntv V6.0
SOFTWARE\Wow6432Node\Torntv V7.0
SOFTWARE\Wow6432Node\Torntv V9.0
SOFTWARE\Wow6432Node\V9.0 Torntv 1.1
SYSTEM\ControlSet001\services\eventlog\Application\Torntv
SYSTEM\ControlSet001\services\trntv
SYSTEM\ControlSet002\services\eventlog\Application\Torntv
SYSTEM\ControlSet002\services\trntv
SYSTEM\CurrentControlSet\services\eventlog\Application\Torntv
SYSTEM\CurrentControlSet\services\trntv
Directory
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\TornTV.com
%APPDATA%\Microsoft\Windows\Start Menu\Programs\TornTV.com
%APPDATA%\TornTV.com
%LOCALAPPDATA%\Google\Chrome\User Data\Default\databases\chrome-extension_ahmilhmcinpmpohfoiccaplbhgelbnim_0
%LOCALAPPDATA%\Google\Chrome\User Data\Default\databases\chrome-extension_lmnbobhffedhdhfpcjkjphcfpeeiocdn_0
%LOCALAPPDATA%\Google\Chrome\User Data\Default\eikjfnpbaomplficjoennadfnacbmiaa
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\ahmilhmcinpmpohfoiccaplbhgelbnim
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\bicnnkjibmphdeigoodpjlcklcnaobdj
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\jbpkiefagocgkmemidfngdkamloieekf
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\lmnbobhffedhdhfpcjkjphcfpeeiocdn
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Local Extension Settings\ahmilhmcinpmpohfoiccaplbhgelbnim
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Local Extension Settings\iflfhlolgckmfkmeoghdfanlloginofg
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Local Extension Settings\lmnbobhffedhdhfpcjkjphcfpeeiocdn
%PROGRAMFILES%\TheTorntv V10
%PROGRAMFILES%\TheTorntvs V10 1.1 -
%PROGRAMFILES%\TornPlusTV_version1.11
%PROGRAMFILES%\Torntv 2
%PROGRAMFILES%\Torntv V6.0
%PROGRAMFILES%\Torntv V7.0
%PROGRAMFILES%\Torntv V9.0
%PROGRAMFILES%\TornTV.com
%PROGRAMFILES(x86)%\TheTorntv V10
%PROGRAMFILES(x86)%\TheTorntvs V10 1.1 -
%PROGRAMFILES(x86)%\TornPlusTV_version1.11
%PROGRAMFILES(x86)%\Torntv 2
%PROGRAMFILES(x86)%\Torntv V6.0
%PROGRAMFILES(x86)%\Torntv V7.0
%PROGRAMFILES(x86)%\Torntv V9.0
%PROGRAMFILES(x86)%\TornTV.com
%USERPROFILE%\Local Settings\Application Data\Google\Chrome\User Data\Default\databases\chrome-extension_lmnbobhffedhdhfpcjkjphcfpeeiocdn_0
%USERPROFILE%\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ahmilhmcinpmpohfoiccaplbhgelbnim
%UserProfile%\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jbpkiefagocgkmemidfngdkamloieekf
%USERPROFILE%\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lmnbobhffedhdhfpcjkjphcfpeeiocdn
%USERPROFILE%\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Extension Settings\ahmilhmcinpmpohfoiccaplbhgelbnim
%USERPROFILE%\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Extension Settings\lmnbobhffedhdhfpcjkjphcfpeeiocdn
%USERPROFILE%\Start Menu\Programs\TornTV.com
File name without path
chrome-extension_ahmilhmcinpmpohfoiccaplbhgelbnim_0.localstorage
chrome-extension_ahmilhmcinpmpohfoiccaplbhgelbnim_0.localstorage-journal
chrome-extension_bicnnkjibmphdeigoodpjlcklcnaobdj_0.localstorage
chrome-extension_bicnnkjibmphdeigoodpjlcklcnaobdj_0.localstorage-journal
chrome-extension_iflfhlolgckmfkmeoghdfanlloginofg_0.localstorage
chrome-extension_iflfhlolgckmfkmeoghdfanlloginofg_0.localstorage-journal
chrome-extension_jbpkiefagocgkmemidfngdkamloieekf_0.localstorage
chrome-extension_jbpkiefagocgkmemidfngdkamloieekf_0.localstorage-journal
chrome-extension_lmnbobhffedhdhfpcjkjphcfpeeiocdn_0.localstorage
chrome-extension_lmnbobhffedhdhfpcjkjphcfpeeiocdn_0.localstorage-journal
http_www.torntv-tvv.org_0.localstorage
http_www.torntv-tvv.org_0.localstorage-journal
Torntv Downloader.lnk
TornTv.lnk
Regexp file mask
%TEMP%\Torntv V9.0Installer_[RANDOM CHARACTERS].log
%windir%\Tasks\2e10d0f9-1239-4dc7-85f8-42db6a7eaea5[RANDOM CHARACTERS].job
CLSID
{11111111-1111-1111-1111-110311551178}
{11111111-1111-1111-1111-110411591160}
{11111111-1111-1111-1111-110411901140}
{11111111-1111-1111-1111-110511131190}
{22222222-2222-2222-2222-220322552278}
{22222222-2222-2222-2222-220422592260}
{22222222-2222-2222-2222-220422902240}
{22222222-2222-2222-2222-220522132290}
{44444444-4444-4444-4444-440344554478}
{44444444-4444-4444-4444-440444594460}
{44444444-4444-4444-4444-440444904440}
{44444444-4444-4444-4444-440544134490}
{55555555-5555-5555-5555-550355555578}
{55555555-5555-5555-5555-550455595560}
{55555555-5555-5555-5555-550455905540}
{55555555-5555-5555-5555-550555135590}
{66666666-6666-6666-6666-660366556678}
{66666666-6666-6666-6666-660466596660}
{66666666-6666-6666-6666-660466906640}
{66666666-6666-6666-6666-660566136690}

More Details on TornTV Hijacker

The following URL's were found:
Tip: We recommend blocking the domain names as well as the IP addresses associated with them.
  • torntv-downloader-dl.info
  • torntv-downloader.com
  • torntv-tvv.org
  • torntv.com

Site Disclaimer

Enigmasoftware.com is not associated, affiliated, sponsored or owned by the malware creators or distributors mentioned on this article. This article should NOT be mistaken or confused in being associated in any way with the promotion or endorsement of malware. Our intent is to provide information that will educate computer users on how to detect, and ultimately remove, malware from their computer with the help of SpyHunter and/or manual removal instructions provided on this article.

This article is provided "as is" and to be used for educational information purposes only. By following any instructions on this article, you agree to be bound by the disclaimer. We make no guarantees that this article will help you completely remove the malware threats on your computer. Spyware changes regularly; therefore, it is difficult to fully clean an infected machine through manual means.

Leave a Reply

Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.