Home Malware Programs Adware TowerTilt

TowerTilt

Posted: March 13, 2014

Threat Metric

Ranking: 14,779
Threat Level: 2/10
Infected PCs: 4,335
First Seen: March 13, 2014
Last Seen: October 7, 2023
OS(es) Affected: Windows


TowerTilt is adware that may display unwanted pop-up ads and messages when computer users browse the Web. TowerTilt may be distributed and installed into the Web browsers such as Internet Explorer, Google Chrome and Mozilla Firefox through packed free applications that computer users download from questionable download websites. Once installed on the PC, TowerTilt may show the text link, transitional, interstitial, search, banner, and full page ads and messages in numerous websites such as Facebook, Google, Wikipedia, and other well-known websites. The intrusive pop-up messages and advertisements of TowerTilt that may emerge on the mentioned websites have nothing in common with them, they are sent by the authors of this adware. TowerTilt may be created to make money from clicks on pop-up messages and ads.

Aliases

Towit [AVG]AdWare.SpadeCast [Ikarus]BrowseSmart [Sophos]Generic_r.KF [AVG]GrayWare[AdWare:not-a-virus]/Win32.LinkSwift [Antiy-AVL]Trojan.BPlug.46 [DrWeb]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\TowerTilt\bin\TowerTilt.PurBrowse.exe File name: TowerTilt.PurBrowse.exe
Size: 239.39 KB (239392 bytes)
MD5: 0d3d764bd01e5bf5b6c51b0f3318a223
Detection count: 239
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\TowerTilt\bin
Group: Malware file
Last Updated: June 2, 2014
%PROGRAMFILES%\TowerTilt\TowerTilt.FirstRun.exe File name: TowerTilt.FirstRun.exe
Size: 1.12 MB (1122592 bytes)
MD5: 449ef011961cfff64071b03be3884835
Detection count: 91
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\TowerTilt
Group: Malware file
Last Updated: June 2, 2014
%PROGRAMFILES%\TowerTilt\bin\TowerTilt.PurBrowse.exe File name: TowerTilt.PurBrowse.exe
Size: 239.39 KB (239392 bytes)
MD5: 91de8d9f82df4ee16182275bcdfcf504
Detection count: 89
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\TowerTilt\bin
Group: Malware file
Last Updated: June 2, 2014
%PROGRAMFILES%\TowerTilt\TowerTilt.FirstRun.exe File name: TowerTilt.FirstRun.exe
Size: 1.12 MB (1122592 bytes)
MD5: 6434af61b558f1424530d31080ef69ce
Detection count: 84
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\TowerTilt
Group: Malware file
Last Updated: June 2, 2014
%PROGRAMFILES(x86)%\TowerTilt\TowerTilt.FirstRun.exe File name: TowerTilt.FirstRun.exe
Size: 1.12 MB (1122592 bytes)
MD5: 62f190de1100aa80ceaed4d13e588022
Detection count: 80
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\TowerTilt
Group: Malware file
Last Updated: June 2, 2014
%PROGRAMFILES%\TowerTilt\bin\utilTowerTilt.exe File name: utilTowerTilt.exe
Size: 317.72 KB (317728 bytes)
MD5: 0493846b1659410fe6307b9de48a4d6a
Detection count: 75
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\TowerTilt\bin
Group: Malware file
Last Updated: June 2, 2014
%PROGRAMFILES%\TowerTilt\TowerTilt.FirstRun.exe File name: TowerTilt.FirstRun.exe
Size: 1.12 MB (1122592 bytes)
MD5: 7d11de09c695103e46a28a1c0783932c
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\TowerTilt
Group: Malware file
Last Updated: June 2, 2014
%PROGRAMFILES(x86)%\TowerTilt\TowerTilt.FirstRun.exe File name: TowerTilt.FirstRun.exe
Size: 1.12 MB (1122592 bytes)
MD5: cc0e06d02a602bfc4ab1e3524d257cde
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\TowerTilt
Group: Malware file
Last Updated: June 2, 2014
%PROGRAMFILES(x86)%\TowerTilt\TowerTiltuninstall.exe File name: TowerTiltuninstall.exe
Size: 239.95 KB (239957 bytes)
MD5: 5be9bdb8866e470ecb8489e79c10f2ef
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\TowerTilt
Group: Malware file
Last Updated: June 2, 2014
system32\drivers\{587cb346-a3d8-4884-b39b-f0ed918b6f96}Gt64.sys File name: {587cb346-a3d8-4884-b39b-f0ed918b6f96}Gt64.sys
Size: 60.09 KB (60096 bytes)
MD5: 423fce691d0e2dd29252f2f405dcd9af
Detection count: 44
File type: System file
Mime Type: unknown/sys
Path: system32\drivers
Group: Malware file
Last Updated: June 13, 2014
%PROGRAMFILES%\TowerTilt\updater.exe File name: updater.exe
Size: 109.56 KB (109568 bytes)
MD5: 105e7a05886c587522d4564908d4c065
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\TowerTilt
Group: Malware file
Last Updated: June 2, 2014
%PROGRAMFILES%\TowerTilt\TowerTiltuninstall.exe File name: TowerTiltuninstall.exe
Size: 238.81 KB (238816 bytes)
MD5: 6c3957418cf4017c82dd30c4547e3f6c
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\TowerTilt
Group: Malware file
Last Updated: June 2, 2014
%PROGRAMFILES(x86)%\TowerTilt\TowerTiltuninstall.exe File name: TowerTiltuninstall.exe
Size: 240.39 KB (240394 bytes)
MD5: a8c1ee44790cb332908fd7b7ad4903b5
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\TowerTilt
Group: Malware file
Last Updated: June 2, 2014
system32\drivers\{587cb346-a3d8-4884-b39b-f0ed918b6f96}Gt64.sys File name: {587cb346-a3d8-4884-b39b-f0ed918b6f96}Gt64.sys
Size: 60.09 KB (60096 bytes)
MD5: d8d478abbe4bce7e5d4e64e2f8639707
Detection count: 30
File type: System file
Mime Type: unknown/sys
Path: system32\drivers
Group: Malware file
Last Updated: June 13, 2014
%PROGRAMFILES%\TowerTilt\updateTowerTilt.exe File name: updateTowerTilt.exe
Size: 316.7 KB (316704 bytes)
MD5: df004791d232e0df63c7c29825a45d1c
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\TowerTilt
Group: Malware file
Last Updated: June 2, 2014
%PROGRAMFILES%\TowerTilt\TowerTilt.FirstRun.exe File name: TowerTilt.FirstRun.exe
Size: 1.12 MB (1122592 bytes)
MD5: 1160bcd4195abdf8c8ba8557c4ea8363
Detection count: 20
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\TowerTilt
Group: Malware file
Last Updated: June 2, 2014
%PROGRAMFILES%\TowerTilt\TowerTilt.FirstRun.exe File name: TowerTilt.FirstRun.exe
Size: 1.12 MB (1122592 bytes)
MD5: 6ccf5bd6188a062ac7b7aef18ab0c67b
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\TowerTilt
Group: Malware file
Last Updated: June 2, 2014
%PROGRAMFILES%\TowerTilt\TowerTilt.FirstRun.exe File name: TowerTilt.FirstRun.exe
Size: 1.12 MB (1122592 bytes)
MD5: 8a927d0005ac7be12af0bdf7386715b6
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\TowerTilt
Group: Malware file
Last Updated: June 2, 2014
%PROGRAMFILES(x86)%\TowerTilt\TowerTilt.FirstRun.exe File name: TowerTilt.FirstRun.exe
Size: 1.12 MB (1122592 bytes)
MD5: de43778211214c6df5cacfdc3a18811e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\TowerTilt
Group: Malware file
Last Updated: June 2, 2014
%PROGRAMFILES(x86)%\TowerTilt\TowerTiltuninstall.exe File name: TowerTiltuninstall.exe
Size: 239.61 KB (239613 bytes)
MD5: 8e5435f614fb1f79f97f8b3f136839a5
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\TowerTilt
Group: Malware file
Last Updated: June 2, 2014
system32\drivers\{587cb346-a3d8-4884-b39b-f0ed918b6f96}t64.sys File name: {587cb346-a3d8-4884-b39b-f0ed918b6f96}t64.sys
Size: 60.09 KB (60096 bytes)
MD5: b9457f59ab7bee3ecc1eeed58ec28bae
Detection count: 5
File type: System file
Mime Type: unknown/sys
Path: system32\drivers
Group: Malware file
Last Updated: June 13, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{3603F80E-BFC2-4EB6-BF31-1ED075CE4DC1}{53D1F32A-A4E1-493C-8830-A4F3599A667F}{716347DC-3B2C-494C-8E63-681862B6E122}HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{53D1F32A-A4E1-493C-8830-A4F3599A667F}SOFTWARE\Microsoft\Tracing\TowerTilt_RASAPI32SOFTWARE\Microsoft\Tracing\TowerTilt_RASMANCSSOFTWARE\Microsoft\Tracing\updateTowerTilt_RASAPI32SOFTWARE\Microsoft\Tracing\updateTowerTilt_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{53D1F32A-A4E1-493C-8830-A4F3599A667F}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{53D1F32A-A4E1-493C-8830-A4F3599A667F}SOFTWARE\TowerTiltSOFTWARE\Wow6432Node\Microsoft\Tracing\TowerTilt_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\TowerTilt_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\updateTowerTilt_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateTowerTilt_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{53D1F32A-A4E1-493C-8830-A4F3599A667F}SOFTWARE\Wow6432Node\TowerTiltSYSTEM\ControlSet001\services\eventlog\Application\Update TowerTiltSYSTEM\ControlSet001\services\eventlog\Application\Util TowerTiltSYSTEM\ControlSet001\services\Update TowerTiltSYSTEM\ControlSet001\services\Util TowerTiltSYSTEM\ControlSet002\services\eventlog\Application\Util TowerTiltSYSTEM\ControlSet002\services\Util TowerTiltSYSTEM\CurrentControlSet\services\eventlog\Application\Update TowerTiltSYSTEM\CurrentControlSet\services\eventlog\Application\Util TowerTiltSYSTEM\CurrentControlSet\services\Update TowerTiltSYSTEM\CurrentControlSet\services\Util TowerTiltHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}TowerTilt

Additional Information

The following directories were created:
%PROGRAMFILES%\TowerTilt%PROGRAMFILES(x86)%\TowerTilt%TEMP%\TowerTilt
The following URL's were detected:
TowerTilt
Loading...