Home Malware Programs Adware Claria

Claria

Posted: May 2, 2006

Claria is known by a number of names such as GAIN and Gator. Claria is the distributor of many softwares which are offered free, which is supported by advertising from the GAIN Network. Claria loads an advertising module called OfferCompanion, which displays pop-up ads when visiting some Web sites. Such ads may or may not be targeted, but are injected with popups, and are not merely displayed within the form of an ad-sponsored application.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 cmesys.exe
    2 fsg_3202.exe
    3 fsg_4104.exe
    4 fsg_6106.exe
    5 gain_trickler.exe
    6 gain_trickler_3102aawlog.txt
    7 gain_trickler_3202.exe
    8 gainplugin.dll
    9 gator.exe
    10 gatorstubsetup.exe
    11 ginst_001_1234_4201.exe
    12 gmt.exe
    13 gta00135ae5.tmp
    14 gta001dc575.tmp
    15 guninstaller.exe
    16 pdpsetup5105.ex_
    17 trickler4010_bic_gatorws_4010.exe
    18 trickler4104_bic_gatordb_1234_4104.exe
    19 trickler_bic_gatorpt_4010.exe
    20 trickler_bic_gatorwebsecure_1234_4201.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\cmesys
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}42040530-2221-4EF7-8F16-9779AB7AAA9842040531-2221-4EF7-8F16-9779AB7AAA9842040532-2221-4EF7-8F16-9779AB7AAA9821ffb6c0-0da1-11d5-a9d5-00500413153c

Related Posts

Loading...