ADW_GAMEPLABS
Adware.GamePlayLabs (Malwarebytes); GamePlayLabs (v) (Sunbelt); Win32/Toolbar.CrossRider.B (ESET-NOD32); ADWARE/CrossRider.Gen2 (Avira); Toolbar.Win32.CrossRider (Ikarus); Win32:Crossrider-AI [PUP] (Avast); Adware.GamePlayLabs.17 (DrWeb)
Windows
Threat Type:
Adware
Destructiveness:
No
Encrypted:
In the wild::
Yes
OVERVIEW
Llega como componente integrado en paquetes de malware/grayware/spyware.
TECHNICAL DETAILS
Detalles de entrada
Llega como componente integrado en paquetes de malware/grayware/spyware.
Instalación
Infiltra los archivos siguientes:
- %Program Files%\{Application Name}\{Application Name}.dll
- %Program Files%\{Application Name}\{Application Name}.exe
- %Program Files%\{Application Name}\{Application Name}.ico
- %Program Files%\{Application Name}\Uninstall.exe
- %AppDataLocal%\{Application Name}\Chrome\{Application Name}.crx
- %User Temp%\{Application Name}Installer_{number}.log
- %User Temp%\ns{random}.tmp\{Application Name}.xpi
- %User Temp%\ns{random}.tmp\{Application Name}_tmp
- %User Temp%\ns{random}.tmp\{App ID}_tmp
- %User Temp%\ns{random}.tmp\CleanChromePrefs.vbs
- %User Temp%\ns{random}.tmp\Dialer.dll
- %User Temp%\ns{random}.tmp\ExecDos.dll
- %User Temp%\ns{random}.tmp\inetc.dll
- %User Temp%\ns{random}.tmp\md5dll.dll
- %User Temp%\ns{random}.tmp\nsislog.dll
- %User Temp%\ns{random}.tmp\nsisos.dll
- %User Temp%\ns{random}.tmp\Processes.dll
- %User Temp%\ns{random}.tmp\RemoveFromList.vbs
- %User Temp%\ns{random}.tmp\StdUtils.dll
- %User Temp%\ns{random}.tmp\System.dll
- %User Temp%\ns{random}.tmp\UserInfo.dll
- %User Temp%\ns{random}.tmp\ZipDLL.dll
(Nota: %Program Files% es la carpeta Archivos de programa predeterminada, que suele estar en C:\Archivos de programa).
. %User Temp% es la carpeta Temp del usuario activo, que en el caso de Windows 2000, XP y Server 2003 suele estar en C:\Documents and Settings\{nombre de usuario}\Local Settings\Temp).)Crea las carpetas siguientes:
- %User Temp%\ns{random}.tmp
- %Program Files%\{Application Name}
- %AppDataLocal%\{Application Name}
- %Application Data%\Mozilla\Firefox\Profiles\{random}.default\extensions\crossriderapp{App ID}@crossrider.com
Otras modificaciones del sistema
Agrega las siguientes entradas de registro como parte de la rutina de instalación:
HKEY_CURRENT_USER\Software\{Application Name}
HKEY_CURRENT_USER\Software\{Application Name}\
Installer
HKEY_CURRENT_USER\Software\Crossrider
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp000{App ID}.BHO
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp000{App ID}.FBAp
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp000{App ID}.Sandbox
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{11111111-1111-1111-1111-110011{ID}11{ID}}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{22222222-2222-2222-2222-220022{ID}22{ID}}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{33333333-3333-3333-3333-330033{ID}33{ID}}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{44444444-4444-4444-4444-440044{ID}44{ID}}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{55555555-5555-5555-5555-550055{ID}55{ID}}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{66666666-6666-6666-6666-660066{ID}66{ID}}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{77777777-7777-7777-7777-770077{ID}77{ID}}
Agrega las siguientes entradas de registro:
HKEY_CURRENT_USER\Software\{Application Name}\
Installer
Folder = "%Program Files%\{Application Name}"
HKEY_CURRENT_USER\Software\Crossrider
215AppVerifier = "{hex values}"
HKEY_CURRENT_USER\Software\Crossrider
Bic = "{hex values}"
HKEY_CURRENT_USER\Software\Crossrider
Verifier = "{hex values}"
HKEY_CURRENT_USER\Software\Crossrider\
Testing
IsTesting = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp000{App ID}.BHO
(Default) = "CrossriderApp000{App ID}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp000{App ID}.BHO\CLSID
(Default) = "{11111111-1111-1111-1111-110011{ID}11{ID}}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp000{App ID}.BHO\CurVer
(Default) = "CrossriderApp000{App ID}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp000{App ID}.BHO.1
(Default) = "CrossriderApp000{App ID}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp000{App ID}.BHO.1\CLSID
(Default) = "{11111111-1111-1111-1111-110011{ID}11{ID}}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp000{App ID}.FBApi
(Default) = "CrossriderApp000{App ID}.FBApi"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp000{App ID}.FBApi\CLSID
(Default) = "{33333333-3333-3333-3333-330033{ID}33{ID}}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp000{App ID}.FBApi\CurVer
(Default) = "CrossriderApp000{App ID}.FBApi.1"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp000{App ID}.FBApi.1
(Default) = "CrossriderApp000{App ID}.FBApi"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp000{App ID}.FBApi.1\CLSID
(Default) = "{33333333-3333-3333-3333-330033{ID}33{ID}}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp000{App ID}.Sandbox
(Default) = "CrossriderApp000{App ID}.Sandbox"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp000{App ID}.Sandbox\CLSID
(Default) = "{22222222-2222-2222-2222-220022{ID}22{ID}}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp000{App ID}.Sandbox\CurVer
(Default) = "CrossriderApp000{App ID}.Sandbox"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp000{App ID}.Sandbox.1
(Default) = "CrossriderApp000{App ID}.Sandbox"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CrossriderApp000{App ID}.Sandbox.1\CLSID
(Default) = "{22222222-2222-2222-2222-220022{ID}22{ID}}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{11111111-1111-1111-1111-110011{ID}11{ID}}
(Default) = "{Application Name}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{11111111-1111-1111-1111-110011{ID}11{ID}}\InprocServer32
(Default) = "%Program Files%\{Application Name}\{Application Name}.dll"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{11111111-1111-1111-1111-110011{ID}11{ID}}\ProgID
(Default) = "CrossriderApp000{App ID}.BHO.1"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{11111111-1111-1111-1111-110011{ID}11{ID}}\TypeLib
(Default) = "{44444444-4444-4444-4444-440044{ID}44{ID}}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{11111111-1111-1111-1111-110011{ID}11{ID}}\VersionIndependentProgID
(Default) = "CrossriderApp000{App ID}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{22222222-2222-2222-2222-220022{ID}22{ID}}
(Default) = "CrossriderApp000{App ID}.Sandbox"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{22222222-2222-2222-2222-220022{ID}22{ID}}\InprocServer32
(Default) = "%Program Files%\{Application Name}\{Application Name}.dll"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{22222222-2222-2222-2222-220022{ID}22{ID}}\ProgID
(Default) = "CrossriderApp000{App ID}.Sandbox.1"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{22222222-2222-2222-2222-220022{ID}22{ID}}\TypeLib
(Default) = "{44444444-4444-4444-4444-440044{ID}44{ID}}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{22222222-2222-2222-2222-220022{ID}22{ID}}\VersionIndependentProgID
(Default) = "CrossriderApp000{App ID}.Sandbox"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{33333333-3333-3333-3333-330033{ID}33{ID}}
(Default) = "CrossriderApp000{App ID}.FBApi"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{33333333-3333-3333-3333-330033{ID}33{ID}}\InprocServer32
(Default) = "%Program Files%\{Application Name}\{Application Name}.dll"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{33333333-3333-3333-3333-330033{ID}33{ID}}\ProgID
(Default) = "CrossriderApp000{App ID}.FBApi.1"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{33333333-3333-3333-3333-330033{ID}33{ID}}\TypeLib
(Default) = "{44444444-4444-4444-4444-440044{ID}44{ID}}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{33333333-3333-3333-3333-330033{ID}33{ID}}\VersionIndependentProgID
(Default) = "CrossriderApp000{App ID}.FBApi"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{55555555-5555-5555-5555-550055{ID}55{ID}}
(Default) = "ICrossriderBHO"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{55555555-5555-5555-5555-550055{ID}55{ID}}\TypeLib
(Default) = "{44444444-4444-4444-4444-440044{ID}44{ID}}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{66666666-6666-6666-6666-660066{ID}66{ID}}
(Default) = "ISandBox"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{66666666-6666-6666-6666-660066{ID}66{ID}}\TypeLib
(Default) = "{44444444-4444-4444-4444-440044{ID}44{ID}}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{77777777-7777-7777-7777-770077{ID}77{ID}}
(Default) = "IFBApi"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Interface\{77777777-7777-7777-7777-770077{ID}77{ID}}\TypeLib
(Default) = "{44444444-4444-4444-4444-440044{ID}44{ID}}"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{44444444-4444-4444-4444-440044{ID}44{ID}}\1.0
(Default) = "CrossriderApp000{App ID} Type Library"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{44444444-4444-4444-4444-440044{ID}44{ID}}\1.0\
0\win32
(Default) = "%Program Files%\{Application Name}\{Application Name}.dll"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
TypeLib\{44444444-4444-4444-4444-440044{ID}44{ID}}\1.0\
HELPDIR
(Default) = "%Program Files%\{Application Name}"
HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Chrome\Extensions\{random name 1}
path = "%AppDataLocal%\{Application Name}\Chrome\{Application Name}.crx"
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Google\Chrome\Extensions\
{random name 1}
path = "%AppDataLocal%\{Application Name}\Chrome\{Application Name}.crx"
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows\CurrentVersion\
Ext\PreApproved\{11111111-1111-1111-1111-110011{ID}11{ID}}
(Default) = ""
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{11111111-1111-1111-1111-110011{ID}11{ID}}
AppName = "{Application Name}.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Low Rights\ElevationPolicy\
{11111111-1111-1111-1111-110011{ID}11{ID}}
AppPath = "%Program Files%\{Application Name}"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Explorer\
Browser Helper Objects\{11111111-1111-1111-1111-110011{ID}11{ID}}
(Default) = "CrossriderApp000{App ID}"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Ext\
PreApproved\{11111111-1111-1111-1111-110011{ID}11{ID}}
(Default) = ""
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{Application Name}
DisplayIcon = "%Program Files%\{Application Name}\Uninstall.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{Application Name}
DisplayName = "{Application Name}"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{Application Name}
UninstallString = "%Program Files%\{Application Name}\Uninstall.exe"