CoolMirage

Category: Adware and PUAs Protection available since:13 Sep 2013 01:39:28 (GMT)
Type: Unspecified PUA Last Updated:12 Jan 2014 17:25:24 (GMT)

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

CoolMirage  is an installer which bundles legitimate applications with offers for additional third party applications that may be unwanted by the user. Such third party applications are typically installed onto users’ computers by default, but may include an option to ‘opt-out’ during or after the installation process.

Examples of CoolMirage include:

Example 1

File Information

Size
296K
SHA-1
00071bdd23d33f3fccb43ed5d3cabe83280aa68d
MD5
ae7861586206226407e01a231355e141
CRC-32
a1074a43
File type
Windows executable
First seen
2013-09-08

Runtime Analysis

Dropped Files
  • c:\Documents and Settings\test user\Local Settings\Temp\nso4.tmp\1clogo.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nso4.tmp\accept_disabled.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nso4.tmp\decline.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nso4.tmp\accept1.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nso4.tmp\skip.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nso4.tmp\box.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nso4.tmp\close.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nso4.tmp\load_0.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nso4.tmp\accept2.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nso4.tmp\inetc3.dll
  • c:\Documents and Settings\test user\Local Settings\Temp\nso4.tmp\v_sign.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nso4.tmp\accept.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nso4.tmp\lyfdt.txt
  • c:\Documents and Settings\test user\Local Settings\Temp\nso4.tmp\noc
  • c:\Documents and Settings\test user\Local Settings\Temp\nso4.tmp\box3.bmp
    Size
    28K
    SHA-1
    7d022db1acefd9d7eb4b72ae9f37bf8995121f39
    MD5
    6fcba5242e2d35ea798f08bb2feea672
    CRC-32
    c41fb234
    File type
    Device-independent bitmap (DIB) file
    First seen
    2013-07-07
  • c:\Documents and Settings\test user\Local Settings\Temp\nso4.tmp\complist.txt
    Size
    67
    SHA-1
    12dabae37fc6444ff278fec91dd571b2b378a500
    MD5
    1f1e84f8836b74e0ca41689f3f640a35
    CRC-32
    8e9312ad
    File type
    ASCII text / 8-bit Unicode Transformation Format
    First seen
    2013-08-19
  • c:\Documents and Settings\test user\Local Settings\Temp\nso4.tmp\back.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nso4.tmp\System.dll
  • c:\Documents and Settings\test user\Local Settings\Temp\nso4.tmp\accept3.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nso4.tmp\x.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nso4.tmp\dAg
    Size
    144
    SHA-1
    ba19fd75f2725fbc65af0974cc42e2f4114ea682
    MD5
    d4ff5e4a9c975b7653e0392b87e3e712
    CRC-32
    27f96c08
    File type
    ASCII text / 8-bit Unicode Transformation Format
    First seen
    2014-01-11
  • c:\Documents and Settings\test user\Local Settings\Temp\nso4.tmp\back_dis.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nso4.tmp\nsDialogs.dll
  • c:\Documents and Settings\test user\Local Settings\Temp\nso4.tmp\box2.bmp
    Size
    28K
    SHA-1
    fd50c484dcd5e7ee5658716f658a1ad36edaf926
    MD5
    6dd4027352ebf48f6c8d0e8abd11005b
    CRC-32
    c8986403
    File type
    Device-independent bitmap (DIB) file
    First seen
    2013-07-07
Registry Keys Created
  • HKCU\Software\1ClickDownload
    LastInstall0
    30347026
  • HKCR\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
    id0
    11012014
HTTP Requests
  • http://data.torntv.net/country.asp
  • http://torntvz.com/ping.php
DNS Requests
  • data.torntv.net
  • torntvz.com

Example 2

File Information

Size
296K
SHA-1
015b3133b7d717c448d8480e7b619f8e5c658188
MD5
f75d93457071f1a0655a2080fd913a81
CRC-32
f95c05c1
File type
Windows executable
First seen
2013-09-06

Runtime Analysis

Dropped Files
  • c:\Documents and Settings\test user\Local Settings\Temp\nsw4.tmp\lyfdt.txt
  • c:\Documents and Settings\test user\Local Settings\Temp\nsw4.tmp\box3.bmp
    Size
    28K
    SHA-1
    7d022db1acefd9d7eb4b72ae9f37bf8995121f39
    MD5
    6fcba5242e2d35ea798f08bb2feea672
    CRC-32
    c41fb234
    File type
    Device-independent bitmap (DIB) file
    First seen
    2013-07-07
  • c:\Documents and Settings\test user\Local Settings\Temp\nsw4.tmp\back_dis.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsw4.tmp\dAg
    Size
    144
    SHA-1
    4c625bb75973d48c1e52949ace0c34cde85319e0
    MD5
    10f36cc6db7362a0ee308184307276de
    CRC-32
    163cf36a
    File type
    ASCII text / 8-bit Unicode Transformation Format
    First seen
    2014-01-11
  • c:\Documents and Settings\test user\Local Settings\Temp\nsw4.tmp\accept2.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsw4.tmp\decline.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsw4.tmp\accept3.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsw4.tmp\noc
  • c:\Documents and Settings\test user\Local Settings\Temp\nsw4.tmp\box.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsw4.tmp\accept1.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsw4.tmp\complist.txt
    Size
    67
    SHA-1
    12dabae37fc6444ff278fec91dd571b2b378a500
    MD5
    1f1e84f8836b74e0ca41689f3f640a35
    CRC-32
    8e9312ad
    File type
    ASCII text / 8-bit Unicode Transformation Format
    First seen
    2013-08-19
  • c:\Documents and Settings\test user\Local Settings\Temp\nsw4.tmp\accept.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsw4.tmp\1clogo.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsw4.tmp\close.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsw4.tmp\accept_disabled.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsw4.tmp\box2.bmp
    Size
    28K
    SHA-1
    fd50c484dcd5e7ee5658716f658a1ad36edaf926
    MD5
    6dd4027352ebf48f6c8d0e8abd11005b
    CRC-32
    c8986403
    File type
    Device-independent bitmap (DIB) file
    First seen
    2013-07-07
  • c:\Documents and Settings\test user\Local Settings\Temp\nsw4.tmp\load_0.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsw4.tmp\System.dll
  • c:\Documents and Settings\test user\Local Settings\Temp\nsw4.tmp\nsDialogs.dll
  • c:\Documents and Settings\test user\Local Settings\Temp\nsw4.tmp\inetc3.dll
  • c:\Documents and Settings\test user\Local Settings\Temp\nsw4.tmp\v_sign.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsw4.tmp\skip.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsw4.tmp\back.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsw4.tmp\x.bmp
Registry Keys Created
  • HKCU\Software\1ClickDownload
    LastInstall0
    30347026
  • HKCR\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
    id0
    11012014
HTTP Requests
  • http://data.torntv.net/country.asp
  • http://torntvz.com/ping.php
DNS Requests
  • data.torntv.net
  • torntvz.com

Example 3

File Information

Size
296K
SHA-1
0292271bbb707e1b3a3487d9518be369284e876a
MD5
a86905a42a0e7e409113986c7eec4cdf
CRC-32
6705b22a
File type
Windows executable
First seen
2007-08-19

Runtime Analysis

Dropped Files
  • c:\Documents and Settings\test user\Local Settings\Temp\nsa4.tmp\close.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsa4.tmp\lyfdt.txt
  • c:\Documents and Settings\test user\Local Settings\Temp\nsa4.tmp\box3.bmp
    Size
    28K
    SHA-1
    7d022db1acefd9d7eb4b72ae9f37bf8995121f39
    MD5
    6fcba5242e2d35ea798f08bb2feea672
    CRC-32
    c41fb234
    File type
    Device-independent bitmap (DIB) file
    First seen
    2013-07-07
  • c:\Documents and Settings\test user\Local Settings\Temp\nsa4.tmp\1clogo.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsa4.tmp\load_0.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsa4.tmp\back.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsa4.tmp\System.dll
  • c:\Documents and Settings\test user\Local Settings\Temp\nsa4.tmp\box.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsa4.tmp\dAg
    Size
    144
    SHA-1
    fec34b170bcedb4f89ac7a9dbe804279afad92c8
    MD5
    2e3c222216a3a4501b81d5d1ece7ecdc
    CRC-32
    e840b20e
    File type
    ASCII text / 8-bit Unicode Transformation Format
    First seen
    2014-01-11
  • c:\Documents and Settings\test user\Local Settings\Temp\nsa4.tmp\decline.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsa4.tmp\noc
  • c:\Documents and Settings\test user\Local Settings\Temp\nsa4.tmp\accept1.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsa4.tmp\skip.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsa4.tmp\accept3.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsa4.tmp\accept.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsa4.tmp\nsDialogs.dll
  • c:\Documents and Settings\test user\Local Settings\Temp\nsa4.tmp\complist.txt
    Size
    67
    SHA-1
    12dabae37fc6444ff278fec91dd571b2b378a500
    MD5
    1f1e84f8836b74e0ca41689f3f640a35
    CRC-32
    8e9312ad
    File type
    ASCII text / 8-bit Unicode Transformation Format
    First seen
    2013-08-19
  • c:\Documents and Settings\test user\Local Settings\Temp\nsa4.tmp\x.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsa4.tmp\accept_disabled.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsa4.tmp\accept2.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsa4.tmp\back_dis.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsa4.tmp\v_sign.bmp
  • c:\Documents and Settings\test user\Local Settings\Temp\nsa4.tmp\inetc3.dll
  • c:\Documents and Settings\test user\Local Settings\Temp\nsa4.tmp\box2.bmp
    Size
    28K
    SHA-1
    fd50c484dcd5e7ee5658716f658a1ad36edaf926
    MD5
    6dd4027352ebf48f6c8d0e8abd11005b
    CRC-32
    c8986403
    File type
    Device-independent bitmap (DIB) file
    First seen
    2013-07-07
Registry Keys Created
  • HKCU\Software\1ClickDownload
    LastInstall0
    30347027
  • HKCR\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
    id0
    11012014
HTTP Requests
  • http://data.torntv.net/country.asp
  • http://torntvz.com/ping.php
DNS Requests
  • data.torntv.net
  • torntvz.com

download Try Sophos products for free
Download now