Downloader . CW Gaming (Summary)
Software Name: CW Gaming
Company Name: CrazyWinnings, TopConverting
Product Name: CW Gaming
Classification: Downloader
Website: http://www.crazywinnings.com
Brief:
Uses their games as a mechanism to install additional adware programs. Displays popup advertising.
IMPORTANT!
Some of the Downloader.CW Gaming components
are listed below. The list is compiled as a reference. The list might
not be complete and it doesn't represent instructions for manual removal.
We DO NOT recommend manual removal. Incorrect removal
of certain software might make your computer unstable or even unusable.
Removal of adware component might affect the related ad-supported software.
If you suspect that you have an unwanted instance of CW Gaming
installed on your computer we recommend a free
audit of your system with INAC Anti Spyware.
CW Gaming might create following folders (and inject its files inside
the folders):
- %PROGRAMS%\Games toolbar
- %PROGRAM_FILES%\Games\Icons
- %PROGRAM_FILES%\Games\Images
- %PROGRAM_FILES%\TopConverting
CW Gaming might create following files (some of the files might be
loaded in memory while the software is running):
- %SYSTEM%\anferror.dll
- %DESKTOP%\Arkanoid.lnk
- %PROGRAMS%\Arkanoid.lnk
- %PROGRAMS%\Games toolbar\Games toolbar.lnk
- %PROGRAMS%\Games toolbar\Games Tour.lnk
- %PROGRAMS%\Games toolbar\How To Uninstall.lnk
- %PROGRAM_FILES%\Games\INSTALL.LOG
- %PROGRAM_FILES%\Games\logo.ico
- %PROGRAM_FILES%\Games\tbGame.dll
- %PROGRAM_FILES%\Games\toolbar.cfg
- %PROGRAM_FILES%\Games\UNWISE.EXE
- %WINDOWS%\games.exe
- %WINDOWS%\gxqv.exe
- %WINDOWS%\updatetc.exe
- %WINDOWS%\VT10.exe
- %WINDOWS%\Downloaded Program Files\loader2.ocx
- %SYSTEM%\aetxprxy.dll
- %SYSTEM%\updak.dl_
- %SYSTEM%\ausldp.dll
- %DESKTOP%\F1.lnk
- %PROGRAMS%\F1.lnk
- %PROGRAM_FILES%\Games\TBlogin.users.EffectiveBrand.com.4.5.14.0
- %WINDOWS%\ofybwhmn.exe
- %SYSTEM%\aztiveds.dll
CW Gaming is often accompanied by the following tracking cookies:
- crazywinnings.com
- topconverting.com
CW Gaming might create following registry keys (and inject subkeys
and values):
- HKEY_CLASSES_ROOT\CLSID\{02FFC86E-283E-4FAA-95D6-ADDCA024F30A}
- HKEY_CLASSES_ROOT\CLSID\{313BC6E2-21F8-40FF-B38C-2ED64257E3DF}
- HKEY_CLASSES_ROOT\CLSID\{38601801-2FF5-4A62-95DA-D2007161C1B4}
- HKEY_CLASSES_ROOT\CLSID\{79849612-A98F-45B8-95E9-4D13C7B6B35C}
- HKEY_CLASSES_ROOT\Interface\{4FE82BA0-9335-4D4E-8E98-76409A88F2C1}
- HKEY_CLASSES_ROOT\Interface\{ACE5B10B-92A3-4103-8583-3684BB09409F}
- HKEY_CLASSES_ROOT\LOADER2.Loader2Ctrl.1
- HKEY_CLASSES_ROOT\TPUSN
- HKEY_CLASSES_ROOT\TypeLib\{487E7682-B976-41FB-A944-E8B83689A454}
- HKEY_LOCAL_MACHINE\SOFTWARE\Games
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{79849612-A98F-45B8-95E9-4D13C7B6B35C}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\*/loader2.ocx*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Games toolbar
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TopConverting
- HKEY_LOCAL_MACHINE\SOFTWARE\TopConverting
- HKEY_USERS\*\Software\Games
- HKEY_USERS\*\Software\Games\toolbar
- HKEY_CLASSES_ROOT\CLSID\{FD403D86-1D58-414A-B728-E3AC57B39513}
- HKEY_LOCAL_MACHINE\SOFTWARE\Games\toolbar
CW Gaming might create following registry values:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{02ffc86e-283e-4faa-95d6-addca024f30a}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform|{7D25B201-7C5F-492B-A66C-E03D4736DCB6}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|gxqv
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|tpcupdater
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Games toolbar
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|*\loader2.ocx
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved|{313BC6E2-21F8-40FF-B38C-2ED64257E3DF}
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{02FFC86E-283E-4FAA-95D6-ADDCA024F30A}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform|{4DC6A9E5-D995-4E6E-89BF-D283A817D88C}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|ofybwhmn
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved|{FD403D86-1D58-414A-B728-E3AC57B39513}
CW Gaming might create registry values with following data:
n/a
CW Gaming might insert following entries in the HOSTS file:
n/a
Click
here to scan your computer for CW Gaming free of charge
|