Home Malware Programs Adware GotSmiley

GotSmiley

Posted: March 28, 2006

GotSmiley is an advertising-supported application that allows to use over one thousand of different icons and emoticons in e-mail messages. The software also downloads from the Internet and runs main components of GAIN adware. GotSmiley must be manually installed. It provides a functional uninstaller. The threat automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 gotsmiley.exe
    2 gotsmileyhelper.dll
    3 gsyoutlookaddin.dll
    4 gsysmileylibinfo.dll
    5 gsyupdater.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOTGSYOutlookAddin.GSYAddinObjHKEY_CLASSES_ROOTGSYOutlookAddin.GSYAddinObj.1HKEY_CURRENT_USERSoftwareGator.comGotSmileyHKEY_CURRENT_USERSoftwareMicrosoftOfficeOutlookAddinsGSYOutlookAddin.GSYAddinObjHKEY_LOCAL_MACHINESOFTWAREGator.comAppInfoGotSmileyHKEY_LOCAL_MACHINESOFTWAREGator.comGotSmileyHKEY_LOCAL_MACHINESOFTWAREMicrosoftOfficeOutlookAddinsGSYOutlookAddin.GSYAddinObjHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunGotSmileyHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallGotSmiley
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}B699B1B8-ADD0-4835-8602-1548200FCDD56DA65196-9CF9-48C9-9DB2-28742FCC56BE
Loading...