Downloads/requests other files from Internet.
Registers a 32-bit in-process server DLL.
Registers a Browser Helper Object (Microsoft's Internet Explorer plugin module).
Contains characteristics of an identified security risk.


Technical Details:

Possible Security Risk

Threat CategoryDescription
A potentially unwanted adware program designed to deliver various advertisements to the users' systems


File System Modifications

#Filename(s)File SizeFile HashAlias
1 %AppData%\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\\chrome\pstextlinks.jar 5,046 bytes MD5: 0xD634833584C643B4C316A786B3A2371E
SHA-1: 0x7F318913309F3F273FD54E72005C63E0E846A204
(not available)
2 %AppData%\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\\chrome.manifest 469 bytes MD5: 0xA2AEBA3C4568B49E40497E2D4E4AE968
(not available)
3 %AppData%\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\\components\PlaySushiFF.dll 196,608 bytes MD5: 0x88F28573EF3F089BC734AC562502F269
SHA-1: 0x18764F7C4548F2F662EFE8EE097C98A53F0DD081
(not available)
4 %AppData%\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\\components\PlaySushiFF.xpt 177 bytes MD5: 0xA88796891BEEA6BC1B5A257C0018EAE4
SHA-1: 0xDFA6444D2ED75D07CCEC7A9DC1EC3A39CC0F0F14
(not available)
5 %AppData%\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\\install.rdf 1,338 bytes MD5: 0x9F1F0B8813B7113F9DAA164660B25127
SHA-1: 0xE7D3B93CD3F3E21CFC8907E8840A797D82754AE7
(not available)
6 %ProgramFiles%\PlaySushi\icon.ico 17,542 bytes MD5: 0x94137A92F26381233A4903A2FFB32F16
SHA-1: 0x5998A68D1BD0C19681F659A04350CF2608F1FB1E
(not available)
7 %ProgramFiles%\PlaySushi\PSText.dll 343,552 bytes MD5: 0x586915B1DB918D40A3D81627B0E6F10E
SHA-1: 0xB0EF369D8C41C4EF4567509A85B95F05DE5C78FA
not-a-virus:AdWare.Win32.Sushi.fg [Kaspersky Lab]
Adware:Win32/GameVance [Microsoft]
8 %ProgramFiles%\PlaySushi\psuninst.exe 188,928 bytes MD5: 0x8C5D67E65CCF6F84A159F07271C77A2F
SHA-1: 0x0A14394E36965FF03C519CEC9790D8157B6FD373
Adware:Win32/GameVance [Microsoft]
9 [file and pathname of the sample #1] 1,214,856 bytes MD5: 0xC0D1664E07B5FC30B477345722F32829
SHA-1: 0x68704BC60DE948D10B53B7A04D1CEA0B9C60E5D8 [Kaspersky Lab]
Adware:Win32/GameVance [Microsoft]


Memory Modifications

Process NameProcess FilenameMain Module Size
[filename of the sample #1][file and pathname of the sample #1]1,232,896 bytes


Registry Modifications


Other details

Remote HostPort Number



