Home→Descriptions→AdWare.Win32.Gamevance.hfti
| Published | Jan 24 2013 10:34 GMT |
Adware designed to redirect user searches to other web resources. It is a Windows application (PE-EXE file). 1135840 bytes. Written in C++.
The trojan is installed as an add-in for the following browsers:
Internet Explorer Google Chrome Mozilla FirefoxAfter launching, the trojan carries out the following actions:
pp_installer_mtx
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{21608B66-026F-4DCB-9244-0DACA328DCED}]
[HKCR\CLSID\{21608B66-026F-4DCB-9244-0DACA328DCED}\InprocServer32]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{109E520F-B6D1-492b-BA66-8E3AA6923055}]
[HKCU\Software\Classes\CLSID\{109E520F-B6D1-492b-BA66-8E3AA6923055}\InprocServer32]
[HKCR\CLSID\{109E520F-B6D1-492b-BA66-8E3AA6923055}\InprocServer32]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{098B1077-D8E5-4974-B5D7-A044B88740E6}]
[HKCU\Software\Classes\CLSID\{098B1077-D8E5-4974-B5D7-A044B88740E6}\InprocServer32]
[HKCR\CLSID\{098B1077-D8E5-4974-B5D7-A044B88740E6}\InprocServer32]
then the trojan shuts down, displaying the following message:
Play Pickle You already have required software for playing games.While the intruder resource:
http://pages.pl***ckle.com/aj/inst.phpis sent the following message:
SKIPPED Another client installed
FAILED INVALID_OS
%Program Files%\Play Pickle
%APPDATA%\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@pl***ckle.com
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\PlayPickle]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AEB04B5E-C981-47a9-B847-33EE4C92F6B9}]
[HKCR\CLSID\{AEB04B5E-C981-47a9-B847-33EE4C92F6B9}]
[HKCR\CLSID\{AEB04B5E-C981-47a9-B847-33EE4C92F6B9}\InprocServer32]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
Desktop Weather Bing Toolbar Ask Toolbar Dogpile Toolbar Shop To Win 8loading the files for their installation from the following links:
http://download.pl***ckle.com/weather/installer.exe http://download.pl***ckle.com/asktoolbar/ApnIC11130.dll http://dl.pp.f***dn.com/pp/download/asktoolbar/ApnIC11130.dll http://download.pl***ckle.com/asktoolbar/ApnToolbarInstaller11130.exe http://dl.pp.f***dn.com/pp/download/asktoolbar/ApnToolbarInstaller11130.exe http://download.pl***ckle.com/asktoolbar/PPApnStub11130.exe http://dl.pp.f***dn.com/pp/download/asktoolbar/PPApnStub11130.exe http://dl.pp.f***dn.com/pp/download/dogpiletoolbar/Dogpile_Toolbar.exe http://download.pl***ckle.com/dogpiletoolbar/Dogpile_Toolbar.exe http://dl.pp.f***dn.com/pp/download/shoptowin/ShopToWin8_FF.exe http://download.pl***ckle.com/shoptowin/ShopToWin8_FF.exe http://dl.pp.f***dn.com/pp/download/shoptowin/ShopToWin8_IE.exe http://download.pl***ckle.com/shoptowin/ShopToWin8_IE.exeThe downloaded files are saved in the current user's temporary file directory "%Temp%" under the relevant names.
After a successful download, the files are launched for execution.
http://pages.pl***ckle.com/aj/inst.php http://pages.pl***ckle.com/aj/bund.php http://pages.pl***ckle.com/aj/ty.php
The trojan can track, collect, and redirect user search queries. In response to a user search, a list of links is produced, obtained from the following servers:
cf.pl***ckle.com play***le.net play***kle.com
If your computer has not been protected with anti-virus software and has been infected with malware, you will need to take the following actions to delete this:
Internet Explorer Google Chrome Mozilla Firefox
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\PlayPickle]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AEB04B5E-C981-47a9-B847-33EE4C92F6B9}]
[HKCR\CLSID\{AEB04B5E-C981-47a9-B847-33EE4C92F6B9}]
[HKCR\CLSID\{AEB04B5E-C981-47a9-B847-33EE4C92F6B9}\InprocServer32]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
%Program Files%\Play Pickle
%APPDATA%\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@pl***ckle.com
MD5: 2A94F593D06C6DCA741AC6C71E90E8EA
SHA1: 54D24FD3D471C899AAD607208B9DCF21998FBE51