Threat Database Adware GamePlayLabs

GamePlayLabs

By ESGI Advisor in Adware

Threat Scorecard

Ranking: 10,674
Threat Level: 20 % (Normal)
Infected Computers: 1,874
First Seen: April 29, 2011
Last Seen: September 13, 2023
OS(es) Affected: Windows

GamePlayLabs is a malignant adware application that is distributed through a network of websites that offer shopping discounts and web search help. GamePlayLabs will try to proliferate by sending a link that includes a malicious download to all user's email contacts. GamePlayLabs invades the affected computers through illegitimate browser-hijacking methods or via trojan infections using backdoor techniques to make damage undetected. If you install GamePlayLabs, it will slow down your browser and display lots of irritating advertisements. Meanwhile, the browser add-on will lead you to suspicious websites. GamePlayLabs may lead to unauthorized access to confidential data and hard drive information with a serious possibility of irretrievable data loss and unstable computer performance.

Aliases

15 security vendors flagged this file as malicious.

Anti-Virus Software Detection
AVG Generic4.BKYU
AntiVir Adware/GamePlayLabs.A.331
BitDefender Adware.Generic.181197
Ikarus AdWare.Win32.GamePlayLabs
AhnLab-V3 Trojan/Win32.ADH
AntiVir Adware/GamePlayLabs.A.272
DrWeb Adware.GamePlayLabs.2
Comodo UnclassifiedMalware
BitDefender Adware.Generic.169231
Kaspersky not-a-virus:AdWare.Win32.GamePlayLabs.d
Avast Win32:GamePlayLabs [PUP]
F-Prot W32/GamePlay.B
McAfee Artemis!08450716B70F
Panda Adware/GamePlayLabs
Ikarus Trojan-Spy

SpyHunter Detects & Remove GamePlayLabs

File System Details

GamePlayLabs may create the following file(s):
# File Name MD5 Detections
1. BHO.dll d7dc7dfe31fa56bbf486e947d89c68f3 1,260
2. BHO.dll 91c805b06dc170f3279af1cb7eecc011 35
3. BHOU.dll 8770670ecc483b8f182bd4cab56a9021 4
4. BHO.dll 08450716b70ff3d40544601f8dce0500 4
5. BHO.dll f2de86812b0671ad008f4a7bce0139a4 2
6. %TEMP%\nst41.tmp\UAC.dll
7. %TEMP%\nst41.tmp\nsisos.dll
8. %TEMP%\nst41.tmp\UserInfo.dll
9. %USERPROFILE%\Local Settings\Application Data\GamePlayLabs Plugin\Uninstall.exe
10. %TEMP%\nst41.tmp\inetc.dll
11. %TEMP%\nst41.tmp\nsisXML.dll
12. %USERPROFILE%\Local Settings\Application Data\GamePlayLabs Plugin\BHO.dll
13. %TEMP%\nst41.tmp\System.dll
14. %TEMP%\nst41.tmp\md5dll.dll
15. %TEMP%\RarSFX0\GamePlayLabsInstaller.exe
16. %TEMP%\Cab50.tmp
17. %TEMP%\Tar43.tmp
18. %TEMP%\Tar47.tmp
19. %TEMP%\Cab4E.tmp
20. %TEMP%\Tar4B.tmp
21. %TEMP%\Cab42.tmp
22. %TEMP%\Tar51.tmp
23. %TEMP%\nst41.tmp\install.xml
24. %TEMP%\RarSFX0\Setup.ini
25. %USERPROFILE%\Local Settings\Application Data\GamePlayLabs Plugin\setup.ini
26. %TEMP%\nst41.tmp
27. %TEMP%\Cab48.tmp
28. %TEMP%\Cab52.tmp
29. %TEMP%\Tar49.tmp
30. %TEMP%\Tar4D.tmp
31. %TEMP%\Cab44.tmp
32. %TEMP%\nst41.tmp\tmp
33. %TEMP%\Tar53.tmp
34. %USERPROFILE%\Local Settings\Application Data\GamePlayLabs Plugin\gplplugin.crx
35. %TEMP%\nsd3F.tmp
36. %TEMP%\Cab46.tmp
37. %TEMP%\nsi40.tmp
38. %TEMP%\Cab4A.tmp
39. %TEMP%\Tar45.tmp
40. %TEMP%\Cab4C.tmp
41. %TEMP%\Tar4F.tmp
42. %TEMP%\nst41.tmp\modern-wizard.bmp
43. %TEMP%\RarSFX0\__tmp_rar_sfx_access_check_2092171

Registry Details

GamePlayLabs may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\APPID\{65C994A2-C65A-4A20-BA92-AADAFC0DCE49}\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\BHO.GAMEPLAYLABSBHO\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{984A9162-8891-4D19-8CFE-17648BB4E1EC}\INPROCSERVER32\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{984A9162-8891-4D19-8CFE-17648BB4E1EC}\PROGRAMMABLE\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{8E7AD93B-3E87-423D-947F-A321FA7E31C4}\PROXYSTUBCLSID\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{8E7AD93B-3E87-423D-947F-A321FA7E31C4}\PROXYSTUBCLSID32\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{199C34A4-5436-403F-A250-219E16672570}\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{199C34A4-5436-403F-A250-219E16672570}\1.0\0\WIN32\
HKEY_LOCAL_MACHINE\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{984A9162-8891-4D19-8CFE-17648BB4E1EC}\
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING\NEXTID = 8194
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\LOCKED = 1
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{8E7AD93B-3E87-423D-947F-A321FA7E31C4}\TYPELIB\VERSION = 1.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\DIRECTDRAW\MOSTRECENTAPPLICATION\ID = [PRIVATE SUBNET]
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\GAMEPLAYLABS PLUGIN\UNINSTALLSTRING = "%USERPROFILE%\Local Settings\Application Data\GamePlayLabs Plugin\Uninstall.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\APPID\BHO.DLL\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\BHO.GAMEPLAYLABSBHO.1\CLSID\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\BHO.GAMEPLAYLABSBHO\CLSID\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{984A9162-8891-4D19-8CFE-17648BB4E1EC}\PROGID\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{984A9162-8891-4D19-8CFE-17648BB4E1EC}\VERSIONINDEPENDENTPROGID\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{8E7AD93B-3E87-423D-947F-A321FA7E31C4}\TYPELIB\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{199C34A4-5436-403F-A250-219E16672570}\1.0\HELPDIR\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{199C34A4-5436-403F-A250-219E16672570}\1.0\0\
HKEY_LOCAL_MACHINE\SOFTWARE\GOOGLE\CHROME\
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\GAMEPLAYLABS PLUGIN\
HKEY_CURRENT_USER\SOFTWARE\GAMEPLAYLABS\RULE_/ = 127191511
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\WINDOW_PLACEMENT = [BINARY DATA]
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\APPID\BHO.DLL\APPID = {65C994A2-C65A-4A20-BA92-AADAFC0DCE49}
HKEY_LOCAL_MACHINE\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\OCPHOBFCFAFPCLIBOLPJDAFGAFFKAOCI\PATH = %USERPROFILE%\Local Settings\Application Data\GamePlayLabs Plugin\gplplugin.crx
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{984A9162-8891-4D19-8CFE-17648BB4E1EC}\NOEXPLORER = 1
HKEY_CURRENT_USER\SOFTWARE\GAMEPLAYLABS\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\BHO.GAMEPLAYLABSBHO.1\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\BHO.GAMEPLAYLABSBHO\CURVER\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{984A9162-8891-4D19-8CFE-17648BB4E1EC}\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{984A9162-8891-4D19-8CFE-17648BB4E1EC}\TYPELIB\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{8E7AD93B-3E87-423D-947F-A321FA7E31C4}\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{199C34A4-5436-403F-A250-219E16672570}\1.0\FLAGS\
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{199C34A4-5436-403F-A250-219E16672570}\1.0\
HKEY_LOCAL_MACHINE\SOFTWARE\GOOGLE\
HKEY_LOCAL_MACHINE\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\OCPHOBFCFAFPCLIBOLPJDAFGAFFKAOCI\
HKEY_CURRENT_USER\SOFTWARE\GAMEPLAYLABS\FR = 1271914896
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING\{92780B25-18CC-41C8-B9BE-3C9C571A8263} = 8193
HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{984A9162-8891-4D19-8CFE-17648BB4E1EC}\INPROCSERVER32\THREADINGMODEL = Apartment
HKEY_LOCAL_MACHINE\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\OCPHOBFCFAFPCLIBOLPJDAFGAFFKAOCI\VERSION = 1.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\DIRECTDRAW\MOSTRECENTAPPLICATION\NAME = iexplore.exe
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\GAMEPLAYLABS PLUGIN\DISPLAYNAME = GamePlayLabs Plugin

URLs

GamePlayLabs may call the following URLs:

174.129.215.***:80
174.129.245.**:80
208.187.212.***:80
216.137.35.***:443
69.171.224.**:80
hxxp://d.gameplaylabs.com/ce9237be57719933386c8a88b67bf7a5/*****
hxxp://www.gameplaylabs.com/newuser/584cabc6b3f04d52b7e23ffbf17c3258/*****

Trending

Most Viewed

Loading...