Home Malware Programs Adware MidADdle

MidADdle

Posted: April 2, 2005

MidADdle is adware that delivers targeted, contextual advertisements via various websites. While MidADdle does not use cookies to track your usage in a personally identifiable way, they may use cookies to collect standard information found in a website log file such as IP address, web browser version, etc.

www.MidADdle.com

File System Modifications

  • The following files were created in the system:
    # File Name
    1 buddy.exe
    2 catsrv94.exe
    3 cbjovg8a.dll
    4 cddu.exe
    5 cdosys81.exe
    6 certmgr5.exe
    7 clicks.dll
    8 clicks10016.dll
    9 clicks10017.dll
    10 cqvb.exe
    11 datastore.dll
    12 edi.exe
    13 fhhzqpw3.dll
    14 hdzv.dll
    15 kjyfi.dll
    16 lmf32v.dll
    17 midaddle.dll
    18 midaddleinst10016.exe
    19 midadl-d.exe
    20 uninstaller.exe
    21 wqm1j1u.exe
    22 xfciysai.exe
    23 y1ebvtq.exe
    24 zukepvus.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\software\esynHKEY_LOCAL_MACHINE\software\midaddleHKEY..\..\..\..{RegistryKeys}b526170e-491f-4e29-8bfb-c6157d02fefd\1.0\0\win32c:\programfiles\esyndicate\esyn.dllb526170e-491f-4e29-8bfb-c6157d02fefd\1.0\flags0b526170e-491f-4e29-8bfb-c6157d02fefd\1.0\helpdirc:\programfiles\esyndicate\b526170e-491f-4e29-8bfb-c6157d02fefd\1.0esyn1.0typelibrarye8eaeb34-f7b5-4c55-87ff-720faf53d841searchhelpecb25a48-e6e0-49af-99af-07c763e31389\1.0ecb25a48-e6e0-49af-99af-07c763e31389\1.0\0\win32ecb25a48-e6e0-49af-99af-07c763e31389\1.0\flagsecb25a48-e6e0-49af-99af-07c763e31389\1.0\helpdirHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\rungg1yk81.exeHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runsearch-exeHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}midaddlemiddadledisplaynamemiddadlenomodifymiddadlenorepairmiddadleuninstallstring
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}e8eaeb34-f7b5-4c55-87ff-720faf53d841c5183abc-eb6e-4e05-b8c9-500a16b6cf94ecb25a48-e6e0-49af-99af-07c763e31389b526170e-491f-4e29-8bfb-c6157d02fefd
Loading...