SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  WinPalace
WinPalace is an Adware. Adware, or advertising-supported software, is any software that automatically renders advertisements in order to generate revenue for its author. The advertisements may be in the user interface of the software or on a screen presented to the user during the installation process. It is usually annoying but harmless, unless it is combined with spyware or trackware.

      Process Related Changes
      It creates the following mutex(es):
      • "IESQMMUTEX_0_208"

      It creates the following process(es):
      • C:\Windows\system32\MSIEXEC.EXE [ MSIEXEC.EXE /i \http://fortd.serverdld.eu/36175/cdn/winpalace/WinPalace20130622034203.msi DDC_DID=6131493 DDC_RTGURL=http://www.pckgscdn.eu/dl/TrackSetup/TrackSetup.aspx?DID=6131493%26filename=WinPalace%2Eexe%26CASINONAME=winpalace DDC_DOWNLOAD_AFFID=40786 DDC_UPDATESTATUSURL=http://209.200.154.71:8080/winpalace/Lobby.WebServices/Installer.asmx CUSTOMNAME02=redirectAsData CUSTOMVALUE02=1 CUSTOMNAME03=remoteIP CUSTOMVALUE03=87.245.204.195 CUSTOMNAME04=name CUSTOMNAME05=email CUSTOMNAME06=redirect CUSTOMNAME07=version CUSTOMVALUE07=100 CUSTOMNAME08=camefrom CUSTOMVALUE08=http://www.winpalace.im/ CUSTOMNAME09=adid CUSTOMVALUE09=NULL CUSTOMNAME10=affreferrer CUSTOMVALUE10=http://www.winpalace.im/ SETUPEXEDIR=C:\windows\temp SETUPEXENAME=\a2ec5c7751019bc46a8995294500e735.exe ]

      Network Activity
      It attempts to connect to the following remote servers:
      • ocsp.verisign.net:80 (199.7.xxxxxx)
      • 209.200xxxxxx:8080
      • hasbv.vo.llnwd.net:80 (68.142.xxxxxx)

      We observed the following DNS query/queries:
      • ocsp.verisign.com
      • fortd.serverdld.eu
      • csc3-2010-crl.verisign.com


      Relevant Information