Home Malware Programs Adware TowerTilt

TowerTilt

Posted: March 13, 2014

Threat Metric

Ranking: 19,553
Threat Level: 2/10
Infected PCs: 4,356
First Seen: March 13, 2014
Last Seen: February 1, 2025
OS(es) Affected: Windows


TowerTilt is adware that may display unwanted pop-up ads and messages when computer users browse the Web. TowerTilt may be distributed and installed into the Web browsers such as Internet Explorer, Google Chrome and Mozilla Firefox through packed free applications that computer users download from questionable download websites. Once installed on the PC, TowerTilt may show the text link, transitional, interstitial, search, banner, and full page ads and messages in numerous websites such as Facebook, Google, Wikipedia, and other well-known websites. The intrusive pop-up messages and advertisements of TowerTilt that may emerge on the mentioned websites have nothing in common with them, they are sent by the authors of this adware. TowerTilt may be created to make money from clicks on pop-up messages and ads.

Aliases

Towit [AVG]AdWare.SpadeCast [Ikarus]BrowseSmart [Sophos]Generic_r.KF [AVG]GrayWare[AdWare:not-a-virus]/Win32.LinkSwift [Antiy-AVL]Trojan.BPlug.46 [DrWeb]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\TowerTilt\bin\TowerTilt.PurBrowse.exe File name: TowerTilt.PurBrowse.exe
Size: 239.39 KB (239392 bytes)
MD5: 0d3d764bd01e5bf5b6c51b0f3318a223
Detection count: 239
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\TowerTilt\bin
Group: Malware file
Last Updated: June 2, 2014
%PROGRAMFILES%\TowerTilt\bin\TowerTilt.BrowserAdapter.exe File name: TowerTilt.BrowserAdapter.exe
Size: 95.52 KB (95520 bytes)
MD5: 4f09db0d84e8a05c7df0fe7e90114f26
Detection count: 82
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\TowerTilt\bin
Group: Malware file
Last Updated: June 2, 2014
%PROGRAMFILES%\TowerTilt\bin\utilTowerTilt.exe File name: utilTowerTilt.exe
Size: 317.72 KB (317728 bytes)
MD5: 0493846b1659410fe6307b9de48a4d6a
Detection count: 75
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\TowerTilt\bin
Group: Malware file
Last Updated: June 2, 2014
%PROGRAMFILES(x86)%\TowerTilt\TowerTiltuninstall.exe File name: TowerTiltuninstall.exe
Size: 239.95 KB (239957 bytes)
MD5: 5be9bdb8866e470ecb8489e79c10f2ef
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\TowerTilt
Group: Malware file
Last Updated: June 2, 2014
%PROGRAMFILES%\TowerTilt\updater.exe File name: updater.exe
Size: 109.56 KB (109568 bytes)
MD5: 105e7a05886c587522d4564908d4c065
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\TowerTilt
Group: Malware file
Last Updated: June 2, 2014
system32\drivers\{587cb346-a3d8-4884-b39b-f0ed918b6f96}Gt64.sys File name: {587cb346-a3d8-4884-b39b-f0ed918b6f96}Gt64.sys
Size: 60.09 KB (60096 bytes)
MD5: d8d478abbe4bce7e5d4e64e2f8639707
Detection count: 30
File type: System file
Mime Type: unknown/sys
Path: system32\drivers
Group: Malware file
Last Updated: June 13, 2014
%PROGRAMFILES%\TowerTilt\bin\FilterApp_C.exe File name: FilterApp_C.exe
Size: 238.88 KB (238880 bytes)
MD5: 7e6e2e095f5554a77f1eedd79b355247
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\TowerTilt\bin
Group: Malware file
Last Updated: June 2, 2014
%PROGRAMFILES(x86)%\TowerTilt\bin\FilterApp_C64.exe File name: FilterApp_C64.exe
Size: 287 KB (287008 bytes)
MD5: 9298f66af7bb8506283602c1adb86cd2
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\TowerTilt\bin
Group: Malware file
Last Updated: June 2, 2014
system32\drivers\{587cb346-a3d8-4884-b39b-f0ed918b6f96}t64.sys File name: {587cb346-a3d8-4884-b39b-f0ed918b6f96}t64.sys
Size: 60.09 KB (60096 bytes)
MD5: b9457f59ab7bee3ecc1eeed58ec28bae
Detection count: 5
File type: System file
Mime Type: unknown/sys
Path: system32\drivers
Group: Malware file
Last Updated: June 13, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{3603F80E-BFC2-4EB6-BF31-1ED075CE4DC1}{53D1F32A-A4E1-493C-8830-A4F3599A667F}{716347DC-3B2C-494C-8E63-681862B6E122}HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{53D1F32A-A4E1-493C-8830-A4F3599A667F}SOFTWARE\Microsoft\Tracing\TowerTilt_RASAPI32SOFTWARE\Microsoft\Tracing\TowerTilt_RASMANCSSOFTWARE\Microsoft\Tracing\updateTowerTilt_RASAPI32SOFTWARE\Microsoft\Tracing\updateTowerTilt_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{53D1F32A-A4E1-493C-8830-A4F3599A667F}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{53D1F32A-A4E1-493C-8830-A4F3599A667F}SOFTWARE\TowerTiltSOFTWARE\Wow6432Node\Microsoft\Tracing\TowerTilt_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\TowerTilt_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\updateTowerTilt_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateTowerTilt_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{53D1F32A-A4E1-493C-8830-A4F3599A667F}SOFTWARE\Wow6432Node\TowerTiltSYSTEM\ControlSet001\services\eventlog\Application\Update TowerTiltSYSTEM\ControlSet001\services\eventlog\Application\Util TowerTiltSYSTEM\ControlSet001\services\Update TowerTiltSYSTEM\ControlSet001\services\Util TowerTiltSYSTEM\ControlSet002\services\eventlog\Application\Util TowerTiltSYSTEM\ControlSet002\services\Util TowerTiltSYSTEM\CurrentControlSet\services\eventlog\Application\Update TowerTiltSYSTEM\CurrentControlSet\services\eventlog\Application\Util TowerTiltSYSTEM\CurrentControlSet\services\Update TowerTiltSYSTEM\CurrentControlSet\services\Util TowerTiltHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}TowerTilt

Additional Information

The following directories were created:
%PROGRAMFILES%\TowerTilt%PROGRAMFILES(x86)%\TowerTilt%TEMP%\TowerTilt
The following URL's were detected:
TowerTilt
Loading...