Threat Database Adware Splending Mini-version Truetest

Splending Mini-version Truetest

By GoldSparrow in Adware

Threat Scorecard

Popularity Rank: 15,246
Threat Level: 80 % (High)
Infected Computers: 84
First Seen: September 5, 2017
Last Seen: October 14, 2025
OS(es) Affected: Windows

The Splending Mini-version Truetest is an adware that displays pop-ups and unwanted advertisements on any visited Web pages. The advertisements are shown in boxes that contain coupons, with underlined key words made as in-text advertisements, advertising banners, and pop-up ads as part of its injecting of ads into any website. The Splending Mini-version Truetestmay be part of bundles of free programs that may be downloaded off the Internet. Some of the free download bundles out there do not share what their contents are accurately so that they may end up installing other software, most commonly adware, Bitcoin miners, browser hijackers and more. In such cases, the users may find themselves surprised unpleasantly with a freshly-installed Splending Mini-version Truetest without their knowledge.

Once the Splending Mini-version Truetest ends up installed, whenever users end up browsing the Web, they will experience redirections to other websites and unwanted advertisements during their browsing sessions. The ads are aimed at promoting additional content and its installation, one of questionable origin, such as optimization utilities, browser toolbars and more, all in the name of a pay-per-click source of revenue for the adware publisher. The authors identify themselves under the nickname marina.hamidulina87 in the Google Chrome Store page of the Splending Mini-version Truetest.

The adware's advertisements may appear with different text under the pop-up, such as 'Powered by Splending mini-version truetest,' 'Ads powered by Splending mini-version truetest,' 'Brought to you by Splending mini-version truetest,' 'Ads by Splending mini-version truetest' and 'RocketTab powered by Splending mini-version truetest.'
When a computer is infected with the Splending Mini-version Truetest adware, its presence can be deduced through the following symptoms:

  • Banner advertisements injected into pages during browsing sessions.
  • The activity of affected users on the Web being tracked.
  • Turning random Web page texts into hyperlinks.
  • Additional adware also may be installed on the affected computer automatically.
  • A slowdown in the browser operations or even a tendency to freeze when loading pages on some machines.

Analysis Report

General information

Family Name: Trojan.TrickBooster.A
Signature status: Self Signed

Known Samples

MD5: 3b86bc55d7aa2677bf5051d956880d32
SHA1: 29b4280edb3dc08cac2f074d323a22b707d3c341
SHA256: 76DEAAFB9176B61829B3C082FB04A449B59E4FB85FA088E534258F93B35E4312
File Size: 2.00 MB, 1999328 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
File Description 腾讯电脑管家在线安装程序
File Version 2.0.6.27
Legal Copyright Copyright (C) 1998 - 2018 Tencent. All Rights Reserved.
Product Name 腾讯电脑管家
Product Version 2.0.6.27

Digital Signatures

Signer Root Status
Tencent Technology(Shenzhen) Company Limited DigiCert Assured ID Code Signing CA-1 Self Signed
Tencent Technology(Shenzhen) Company Limited DigiCert SHA2 Assured ID Code Signing CA Self Signed

File Traits

  • dll
  • HighEntropy
  • x86

Files Modified

File Attributes
\device\harddisk0\dr0 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\tencent\deskupdate\globalmgr.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\tencent\deskupdate\globalmgr.db Generic Write,Read Attributes
c:\programdata\tencent\deskupdate\guid.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\tencent\deskupdate\guidinfo.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\tencent\deskupdate\guidlist.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\tencent\deskupdate\guidreport.dat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\tencent\deskupdate\hdd.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\738a.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\tencentdownload\~a6fef\beacon_sdk.dll Generic Read,Generic Execute,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 786496
Show More
c:\users\user\appdata\local\temp\tencentdownload\~a6fef\qqpcdownload.dll Generic Read,Generic Execute,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 786496
c:\users\user\appdata\local\temp\tencentdownload\~a6fef\setup.xml Generic Read,Generic Execute,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 786496
c:\users\user\appdata\roaming\tencent\beacon\bc_0win0dj6vl4uy2kw_09.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\tencent\beacon\bc_0win0dj6vl4uy2kw_09.db-journal Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\tencent\beacon\bc_0win0dj6vl4uy2kw_09.db-shm Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\tencent\beacon\bc_0win0dj6vl4uy2kw_09.db-wal Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\tencent\deskupdate\globalmgr.db Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\roaming\tencent\qmdownload\downloaderrlogfile.log Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\tencent\qqpcmgr\download\version Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
Network Info Queried
  • GetAdaptersInfo
Network Winsock2
  • WSAStartup
Other Suspicious
  • SetWindowsHookEx
Network Winsock
  • connect
  • gethostbyname
  • send
  • setsockopt
  • socket
Network Winhttp
  • WinHttpConnect
  • WinHttpOpen
  • WinHttpOpenRequest
Network Wininet
  • InternetOpen
  • InternetOpenUrl

Trending

Most Viewed

Loading...