Home Malware Programs Adware CashBackBuddy

CashBackBuddy

Posted: March 28, 2006

CashBackBuddy is an adware application that allows to earn rebates for online purchases. However, it also shows commercial advertisements and tracks user Internet activity. CashBackBuddy must be manually installed. It can also get into the computer along with some ad-supported software. The adware automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 cashback.exe
    2 cb.exe
    3 flash.exe
    4 installer_cashback.exe
    5 mscb.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWARECashBackHKEY_LOCAL_MACHINESOFTWAREClassesCB.UrlCatcherHKEY_LOCAL_MACHINESOFTWAREClassesCB.UrlCatcher.1HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionModuleUsage\%Windir%/DownloadedProgramFiles/installer_cashback.exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunCashBackHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionSharedDLLs=%Windir%DownloadedProgramFilesinstaller_cashback.exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallCashBack
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}4EB7BBE8-2E15-424B-9DDB-2CDB9516E2A3C6906A23-4717-4E1F-B6FD-F06EBED124688EEE58D5-130E-4CBD-9C83-35A0564E2468CE188402-6EE7-4022-8868-AB25173A3E14
Loading...