TowerTilt

By GoldSparrow in Adware

Threat Scorecard

Threat Level: 20 % (Normal)
Infected Computers: 1,849
First Seen: March 13, 2014
Last Seen: April 18, 2023
OS(es) Affected: Windows

TowerTilt is adware that may show annoying advertisements and messages when PC users surf the Internet. TowerTilt may spread and integrate itself into the Web browsers such as Internet Explorer, Google Chrome and Mozilla Firefox through bundled free software that PC users download from unreliable download websites. After installation on the computer system, TowerTilt may display the text link, transitional, interstitial, search, banner, and full page ads and banners in various websites such as Google, Facebook, Wikipedia, and other popular websites. The disturbing ads and banners of TowerTilt that show up on the mentioned websites are not related to them, they are delivered by the creators of TowerTilt. TowerTilt may be generated with the goal to generate advertising revenue from clicks on pop-up messages, advertisements and banners.

Aliases

6 security vendors flagged this file as malicious.

Anti-Virus Software Detection
AVG Towit
Ikarus AdWare.SpadeCast
Sophos BrowseSmart
AVG Generic_r.KF
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.LinkSwift
DrWeb Trojan.BPlug.46

SpyHunter Detects & Remove TowerTilt

File System Details

TowerTilt may create the following file(s):
# File Name MD5 Detections
1. TowerTilt.PurBrowse.exe 0d3d764bd01e5bf5b6c51b0f3318a223 102
2. TowerTiltuninstall.exe 7520c110c7c63f3154a3f7b1bba3e16b 45
3. TowerTilt.PurBrowse.exe 91de8d9f82df4ee16182275bcdfcf504 38
4. updater.exe 105e7a05886c587522d4564908d4c065 18
5. updateTowerTilt.exe df004791d232e0df63c7c29825a45d1c 11
6. TowerTilt.FirstRun.exe 1c5053536f8d9b411e80ebdb01a3565c 4
7. TowerTilt.FirstRun.exe 6ccf5bd6188a062ac7b7aef18ab0c67b 4
8. TowerTilt.FirstRun.exe 8a927d0005ac7be12af0bdf7386715b6 2
9. TowerTiltuninstall.exe 8e5435f614fb1f79f97f8b3f136839a5 2
10. {587cb346-a3d8-4884-b39b-f0ed918b6f96}t64.sys b9457f59ab7bee3ecc1eeed58ec28bae 2
11. TowerTilt.FirstRun.exe 1160bcd4195abdf8c8ba8557c4ea8363 1
12. utilTowerTilt.exe 0493846b1659410fe6307b9de48a4d6a 1
13. TowerTiltuninstall.exe a8c1ee44790cb332908fd7b7ad4903b5 1
14. TowerTiltuninstall.exe 6c3957418cf4017c82dd30c4547e3f6c 1
15. updateTowerTilt.exe 35205880127843cd36b2c72d83eb9722 1
16. TowerTilt.FirstRun.exe 62f190de1100aa80ceaed4d13e588022 1
17. TowerTilt.FirstRun.exe 7d11de09c695103e46a28a1c0783932c 1
18. TowerTilt.FirstRun.exe cc0e06d02a602bfc4ab1e3524d257cde 1
19. TowerTilt.FirstRun.exe de43778211214c6df5cacfdc3a18811e 1
20. TowerTilt.FirstRun.exe 449ef011961cfff64071b03be3884835 1
21. TowerTilt.FirstRun.exe 6434af61b558f1424530d31080ef69ce 1
22. TowerTilt.FirstRun.exe 119d0500c21ddc8c9b6171d5026830ec 1
23. TowerTiltuninstall.exe 5be9bdb8866e470ecb8489e79c10f2ef 1
24. {587cb346-a3d8-4884-b39b-f0ed918b6f96}Gt64.sys 423fce691d0e2dd29252f2f405dcd9af 1
25. {587cb346-a3d8-4884-b39b-f0ed918b6f96}Gt64.sys d8d478abbe4bce7e5d4e64e2f8639707 1
More files

Registry Details

TowerTilt may create the following registry entry or registry entries:
CLSID
{3603F80E-BFC2-4EB6-BF31-1ED075CE4DC1}
{53D1F32A-A4E1-493C-8830-A4F3599A667F}
{716347DC-3B2C-494C-8E63-681862B6E122}
Software\Microsoft\Internet Explorer\Approved Extensions\{53D1F32A-A4E1-493C-8830-A4F3599A667F}
SOFTWARE\Microsoft\Tracing\TowerTilt_RASAPI32
SOFTWARE\Microsoft\Tracing\TowerTilt_RASMANCS
SOFTWARE\Microsoft\Tracing\updateTowerTilt_RASAPI32
SOFTWARE\Microsoft\Tracing\updateTowerTilt_RASMANCS
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{53D1F32A-A4E1-493C-8830-A4F3599A667F}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{53D1F32A-A4E1-493C-8830-A4F3599A667F}
SOFTWARE\TowerTilt
SOFTWARE\Wow6432Node\Microsoft\Tracing\TowerTilt_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\TowerTilt_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Tracing\updateTowerTilt_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\updateTowerTilt_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{53D1F32A-A4E1-493C-8830-A4F3599A667F}
SOFTWARE\Wow6432Node\TowerTilt
SYSTEM\ControlSet001\services\eventlog\Application\Update TowerTilt
SYSTEM\ControlSet001\services\eventlog\Application\Util TowerTilt
SYSTEM\ControlSet001\services\Update TowerTilt
SYSTEM\ControlSet001\services\Util TowerTilt
SYSTEM\ControlSet002\services\eventlog\Application\Util TowerTilt
SYSTEM\ControlSet002\services\Util TowerTilt
SYSTEM\CurrentControlSet\services\eventlog\Application\Update TowerTilt
SYSTEM\CurrentControlSet\services\eventlog\Application\Util TowerTilt
SYSTEM\CurrentControlSet\services\Update TowerTilt
SYSTEM\CurrentControlSet\services\Util TowerTilt

Directories

TowerTilt may create the following directory or directories:

%PROGRAMFILES%\TowerTilt
%PROGRAMFILES(x86)%\TowerTilt
%TEMP%\TowerTilt

URLs

TowerTilt may call the following URLs:

TowerTilt

Trending

Most Viewed

Loading...