PlayVolcano

PlayVolcano

Known Malware

by Pinball Corporation

What is PlayVolcano?

PlayVolcano is software application developed by Pinball Corporation. It is most commonly found on computers running Windows 7 with nearly 69.23% of installations running this operating system. PlayVolcano's installer is typically 1.00 MB in size and installs around 4 files.

PlayVolcano is most popular in the United States with 47.37% of installations residing in this country.

PlayVolcano adds 1 scheduled task to the Windows Task Scheduler launching the program at randomly scheduled times.

About PlayVolcano?

PlayVolcano is a web browser plugin that is distributed through various monetization platforms during installation, and it is supported by advertisements. Users may encounter additional banner and in-text link advertisements while using the plugin. The software includes a variety of features designed to modify the default or custom settings of the user's browser, such as the home page and search settings.

Multiple virus scanners have detected malware in PlayVolcano.

PlayVolcanoSA.exe (MD5: f298443fe6f779692caefa4c3d2640cc) has been flagged by 23 scanners:
Scanner Software Result
Avira AntiVir TR/HotBarBZ.A.3
Antiy-AVL AdWare/Win32.HotBar
avast! Win32:HotBar-BZ [Adw]
AVG Skodna.Generic_r.L
Bitdefender Application.Generic.408814
Comodo Security UnclassifiedMalware
Dr.Web Adware.Zango.15
Emsisoft Anti-Malware Riskware.AdWare.Win32.Shopper!IK
eSafe Win32.Trojan
ESET-NOD32 probably a variant of Win32/Adware.180Solutions
F-Prot W32/180Solutions.D.gen
F-Secure Application.Generic.408814
G Data Application.Generic.408814
IKARUS anti.virus not-a-virus:AdWare.Win32.Shopper
Jiangmin Adware/HotBar.kb
K7 AntiVirus Adware
Kaspersky not-a-virus:HEUR:AdWare.Win32.HotBar
Kingsoft AntiVirus Win32.Malware.Generic.a.(kcloud)
McAfee Artemis!F298443FE6F7
McAfee-GW-Edition Artemis!F298443FE6F7
Sophos Hotbar
Symantec WS.Reputation
VIPRE Antivirus Pinball Corporation

Software Behaviors

Scheduled tasks:
  • PlayVolcanoSA.exe is scheduled as a task named 'RunAsStdUser Task' (runs on registration).

Startup Entries

Registry entries:
  • PlayVolcanoSA.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'PlayVolcanoSA' and executes as "C:\users\user\appdata\Local\PlayVolcanoSA\bin\1.0.10.0\PlayVolcanoSA.exe".

Software Details

URL:
https://www.playvolcano.com
Support:
https://www.playvolcano.com/support.html
Installation path:
C:\users\user\appdata\local\playvolcanosa\bin\1.0.10.0
Uninstaller:
"C:\users\user\appdata\Local\PlayVolcanoSA\bin\1.0.10.0\PlayVolcanoUninstaller.exe" Web
Size:
1.00 MB
Language:
English

PlayVolcano Executable Details

Primary executable:
PlayVolcanoSA.exe
Name:
PlayVolcano
Path:
C:\users\user\appdata\local\playvolcanosa\bin\1.0.10.0\PlayVolcanoSA.exe
MD5:
f298443fe6f779692caefa4c3d2640cc
SHA-1:
SHA-256:
Files installed by PlayVolcano
File Type Filename MD5
EXE
9e076d00809036d84101b9256bd6490a
DLL
c116939c51199b3270e4dc8817dc49f5
EXE
f298443fe6f779692caefa4c3d2640cc
EXE
9af6567b7dd0730eef248728e4e3b581