Ads By Quiz Games

By GoldSparrow in Potentially Unwanted Programs

Threat Scorecard

Popularity Rank: 5,478
Threat Level: 80 % (High)
Infected Computers: 20,505
First Seen: June 8, 2015
Last Seen: January 14, 2026
OS(es) Affected: Windows

Quiz Games is a browser add-on, compatible with most modern Windows-based browsers. This browser add-on is promoted as a helpful tool to enhance your online experience. In reality, Quiz Games is nothing more than another advertisement platform. Quiz Games is distributed via the popular and polarizing practice of software bundles. In most cases, users are oblivious to the fact that additional software has been installed on their machine. Once on the computer, Quiz Games will attach itself to your browser(s) and start peddling advertisements. Soon enough, your browsing sessions will be filled with ads and pop-ups, promoting a variety of products. The ads promoted by Quiz Games may expose your computer to threats. Suffice to say, clicking on any ads promoted by Quiz Games is an ill-advised idea. Furthermore, Quiz Games may modify your browser settings, replacing your homepage and default search engine. The search engine queries display skewed data, favoring sponsored links and advertisements. Due to its propagation method, low utility and potentially dangerous habits, Quiz Games is classified as a PUP (Potentially Unwanted Program) with adware capabilities. If you detect Quiz Games on your computer and you do not want its features, you should take action to remove it.

Analysis Report

General information

Family Name: Trojan.Coinminer.GI
Signature status: No Signature

Known Samples

MD5: 0f77adf00868a8855ba7dcf77c2b3405
SHA1: f1839571b044595db5d22ac3b38d9c37feaba3c2
SHA256: 671700BDB178CD7E4DAD430ABEA98B8D0B9EE4FE9484061AF3D5C530C687CFB6
File Size: 9.62 MB, 9616048 bytes
MD5: 17b2a49c7ddaf9878ce3e3f0d6441dc4
SHA1: 52e7504eb3ebd0274ad220b95c74ab11637913c8
SHA256: B44F71BC08CE78208F9AA2CDFD9C4E076707E7343BC04F88C3D86110627A76B3
File Size: 3.41 MB, 3413424 bytes
MD5: 690fec0ea622cc80812d084cba820a46
SHA1: 89f70ab15f2f9858ddf5bf935d8a36cf3eea4a8e
SHA256: 949CF4F396941D4E50DB08907C5BF6F736F47A16AAF4E2A83BAC3EE773A334E7
File Size: 9.62 MB, 9616056 bytes
MD5: c4a38fb5dc43a3be2d2efcc6161a501f
SHA1: 860085f6b4e6251a51210e903eff626e120f8804
SHA256: 476E5347786D12010EB6B51EA20F0F380F26F4788A5C120CD8152D3F6B144D39
File Size: 9.98 MB, 9975296 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Ubisoft
File Description
  • DCIService.exe
  • Ubisoft Streaming Application
File Version 3.0.2.12
Internal Name
  • DCIService.exe
  • StreamingApp
Legal Copyright
  • (c) Ubisoft
  • Copyright (c) 2009
Original Filename
  • DCIService.exe
  • StreamingApp.exe
Product Name Ubisoft Streaming Application
Product Version
  • 3.0.2.12
  • 1.10.0-c1dc4f97

Digital Signatures

Signer Root Status
Lavasoft Software Canada Inc. Entrust Root Certification Authority - G2 Hash Mismatch
UBISOFT ENTERTAINMENT INC. Microsoft Identity Verification Root Certificate Authority 2020 Root Not Trusted

File Traits

  • No Version Info
  • x64

Block Information

Total Blocks: 28,344
Potentially Malicious Blocks: 121
Whitelisted Blocks: 23,486
Unknown Blocks: 4,737

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 ? 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 x x ? ? 0 ? 0 0 x 0 x 0 0 ? ? ? ? ? ? ? x x x x x x x 0 x 0 0 x x x 0 0 ? ? ? 0 0 0 0 0 0 0 0 ? ? 0 ? ? 0 0 0 0 0 ? 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 x x 0 x x x 0 x 0 0 x 0 0 0 0 0 0 ? 0 0 0 x 0 0 0 ? x ? 0 ? x ? 0 ? x ? 0 x 0 x 0 x x 0 x ? x 0 x 0 0 0 0 0 x x x x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 ? 0 1 ? 0 0 0 0 0 0 1 ? 0 ? 1 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 ? x 0 ? x 0 x 0 0 x 0 x 0 0 ? x ? x ? x ? ? 0 x 0 0 ? x x 0 x ? 0 ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 ? x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 ? 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 ? 0 0 0 ? 0 x ? 0 0 ? ? 0 ? 0 ? 0 ? 0 ? ? 0 0 0 ? 0 0 0 0 0 0 ? 0 ? 0 0 0 ? ? 0 ? 0 0 0 0 ? x ? ? 0 0 0 ? 0 0 0 x 0 ? ? 0 0 0 x 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? x x x ? x 0 0 0 0 0 0 0 0 0 1 ? 0 0 0 0 ? 0 ? ? ? 0 ? 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 ? ? 0 0 ? ? 0 ? 0 0 0 0 0 0 0 1 0 0 1 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 1 1 0 0 0 0 0 0 0 1 0 ? ? 0 1 ? 0 1 0 0 0 0 0 ? 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 x 0 0 0 ? ? ? 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? 0 0 ? ? 0 ? ? ? ? ? ? 0 0 0 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 ? ? 0 0 0 0 1 0 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 ? ? ? ? 0 ? 0 ? 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 ? 1 x 1 x 1 ? 1 ? ? 1 ? x 1 ? 1 ? ? 1 ? 0 1 0 0 0 ? ? 1 0 0 1 ? x 0 1 1 ? ? 0 0 0 ? 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 ? ? 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? 0 0 0 ? ? 0 0 0 ? ? 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? 0 0 0 0 ? ? ? ? ? 0 ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 1 ? 0 0 0 0 0 0 ? ? ? ? ? ? 0 ? ? ? 0 0 0 ? 0 0 x ? 0 ? ? 0 0 ? ? 0 ? ? ? ? ? ? 0 0 ? 0 ? 0 ? ? ? ? 0 0 0 0 0 0 0 ? ? ? ? ? 0 ? ? 0 0 ? ? 0 ? 0 0 ? 0 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 ? 0 ? ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? 0 ? ? 0 ? ? 0 ? 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? 0 ? 0 ? ? ? 0 ? 0 ? ? 0 0 0 ? ? ? 0 ? ? ? 0 0 0 0 ? ? ? ? 0 ? ? ? ? ? ? 0 0 0 ? 0 0 0 0 ? ? ? ? ? ? 0 ? ? 0 ? ? ? 0 ? 0 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? 0 ? 0 ? 0 0 0 0 ? ? 0 0 0 0 0 x x ? ? 0 ? ? 0 ? ? ? 0 0 ? ? ? 0 0 ? 0 0 ? ? ? ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 1 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? ? 0 ? ? 0 ? ? 0 0 0 0 ? 0 0 ? 0 ? ? 0 ? ? ? 0 ? ? ? ? 0 ? ? ? ?
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
Show More
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Service Control
  • StartServiceCtrlDispatcher
Network Winsock2
  • WSAStartup

Trending

Most Viewed

Loading...