Should I block it?

98%
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization

VersionsAdditional versions

2, 6, 0, 7 23.08%
2, 6, 0, 4 7.69%
2, 6, 0, 4 7.69%
2, 6, 0, 4 7.69%
2, 6, 0, 4 7.69%
2, 6, 0, 4 23.08%
2, 6, 0, 4 7.69%
2, 6, 0, 4 7.69%
2, 6, 0, 4 7.69%

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegCloseKey, RegOpenKeyA, RegQueryInfoKeyA, RegEnumKeyExA, RegQueryValueExA
iphlpapi.dll
GetBestRoute, GetAdaptersInfo, GetIfTable, GetIpForwardTable
kernel32.dll
IsValidLocale, GetEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsW, FreeEnvironmentStringsA, GetStdHandle, SetHandleCount, GetFileType, SetStdHandle, UnhandledExceptionFilter, HeapCreate, HeapDestroy, GetEnvironmentVariableA, FlushFileBuffers, WriteFile, HeapSize, CompareStringW, CompareStringA, GetCPInfo, LCMapStringW, LCMapStringA, GetVersion, GetCommandLineA, GetStartupInfoA, HeapReAlloc, ExitThread, GetTimeZoneInformation, ExitProcess, RaiseException, Sleep, CreateDirectoryA, GetProcAddress, LoadLibraryA, FreeLibrary, DeleteFileA, GetTempFileNameA, GetTempPathA, OutputDebugStringA, lstrcatA, lstrcpyA, SetLastError, CloseHandle, IsBadCodePtr, OpenProcess, GetLastError, GetModuleHandleA, GetVersionExA, IsBadWritePtr, GetModuleFileNameA, CreateFileA, GetCurrentProcessId, ReadProcessMemory, GetCurrentProcess, lstrcpynA, IsValidCodePage, GetCurrentThread, IsBadReadPtr, HeapFree, GetProcessHeap, SetUnhandledExceptionFilter, GetLocalTime, GetUserDefaultLangID, GetTickCount, GetFileSize, SetFilePointer, ReadFile, SetEndOfFile, lstrcmpiA, ResetEvent, SetEvent, CreateThread, CreateEventA, TerminateThread, WaitForSingleObject, CreateMutexA, GetWindowsDirectoryA, FindClose, FindFirstFileA, MultiByteToWideChar, GetPrivateProfileStringA, SetProcessWorkingSetSize, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, GetCurrentThreadId, TlsAlloc, TlsGetValue, TlsSetValue, GetSystemTimeAsFileTime, GetSystemTime, VirtualProtect, HeapAlloc, VirtualAlloc, SetEnvironmentVariableA, GetSystemDefaultLangID, TerminateProcess, RtlUnwind, WideCharToMultiByte, InterlockedIncrement, InterlockedDecrement, InterlockedExchange, GetLocaleInfoA, EnumSystemLocalesA, GetUserDefaultLCID, GetStringTypeA, GetStringTypeW, GetACP, GetOEMCP, GetLocaleInfoW, lstrlenA, VirtualFree
ole32.dll
CoCreateGuid, CoInitialize, CoCreateInstance, CoUninitialize
rasapi32.dll
RasEnumConnectionsA
urlmon.dll
URLDownloadToFileA
user32.dll
RegisterClassExA, CreateWindowExA, SetWindowPos, ShowWindow, DispatchMessageA, TranslateMessage, UnregisterClassA, PostQuitMessage, DefWindowProcA, wsprintfA, SetLastErrorEx, CharNextA, FindWindowA, PostThreadMessageA, PostMessageA, GetMessageA, LoadCursorA
wininet.dll
InternetReadFile, HttpSendRequestA, HttpEndRequestA, HttpSendRequestExA, HttpOpenRequestA, InternetConnectA, InternetOpenA, InternetCrackUrlA, InternetCloseHandle, HttpQueryInfoA

Orbitnet.exe

P2P service of Orbit Downloader by KORAM GAMES LIMITED (Signed)

Remove Orbitnet.exe
Version:   2, 6, 0, 4
MD5:   104bb4628d7cc116111b27e401844632
SHA1:   a61134a53ff950affef9b1f1f072e3e23c5b0b37
SHA256:   4d2c5b77bdae85af26f23b39d86f4a5473720041567f7022b97df07585b8429d
Warning 4 antivirus scanners has detected malware.

Overview

orbitnet.exe is malware that executes as a process with the local user's privileges. It has been configured with a firewall exception which allows both inbound and outbound network communication without being blocked. This is typically installed with the program Orbit Downloader published by www.orbitdownloader.com. The file is digitally signed by KORAM GAMES LIMITED which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:orbitnet.exe
Publisher:Orbitdownloader.com
Product name:P2P service of Orbit Downloader
Typical file path:C:\Program Files\orbitdownloader\orbitnet.exe
File version:2, 6, 0, 4
Size:544 KB (557,056 bytes)
Certificate
Issued to:KORAM GAMES LIMITED
Authority (CA):VeriSign
Effective date:Thursday, November 8, 2012
Expiration date:Wednesday, January 8, 2014
Digital DNA
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
www.orbitdownloader.com
22% remove
Orbit Downloader is a download manager for Windows that has the ability to grab and download embedded Flash Video files from sites like YouTube, Dailymotion, Metacafe, etc. Orbit Downloader also accelerates downloads by acting as a peer-to-peer client, utilizing bandwidth of other users. Orbit Downloader is an advertising-supported product since it may change the web browser's homepage upon installation and also offers to install softwa...

BehaviorsBehaviors

Windows firewall allowed programs
Exceptions allow programs to access to the Internet through an outbound connections
  • Firewall exception for 'C:\Program Files\Orbitdownloader\orbitnet.exe'
  • Firewall exception for 'C:\Program Files\Orbitdownloader\orbitnet.exe'
  • Firewall exception for 'C:\Program Files\Orbitdownloader\orbitnet.exe'

MalwareMalware detections

Based on 40+ industry antivirus scanners, 4 of them detected the following malware.
Antivirus engineEngine versionDetection
Antiy Labs AVL 2.0.3.7 NetTool/Win32.GushUnleashed
Bkav Security 1.3.0.4923 W32.Clodc92.Trojan.c0bd
Ikarus T3.1.5.6.0 not-a-virus:NetTool.Win32.GushUnleashed
Kaspersky 12.0.0.1221 not-a-virus:NetTool.Win32.GushUnleashed.a

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 30.77%
Windows 7 Home Premium 15.38%
Windows 7 Professional 15.38%
Windows 7 Ultimate 15.38%
Windows Seven Black Edition 7.69%
Windows 8 7.69%
Windows 8 Pro 7.69%

Distribution by countryDistribution by country

United States installs about 30.77% of P2P service of Orbit Downloader.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Toshiba 33.33%
ASUS 16.67%
Hewlett-Packard 16.67%
Dell 16.67%
GIGABYTE 16.67%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE