Home Malware Programs Adware MoneyGainer

MoneyGainer

Posted: March 28, 2006

MoneyGainer is an adware application, which monitors user activity and appends specific code to certain web site addresses. This code allows the threat's author to earn money when the user visits those resources. MoneyGainer can also serve unsolicited commercial advertisements. It regularly contacts a predetermined web server to check for and download updated configuration settings. MoneyGainer must be manually installed. It works as the web browser's add-on and runs every time the user launches Internet Explorer.

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREClassesBookmark.BHOMoneyGainerHKEY_LOCAL_MACHINESOFTWAREClassesBookmark.BHOMoneyGainer.1HKEY_LOCAL_MACHINESOFTWAREiasadc
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}27195441-54B0-4DD3-820C-699AC3EF8D37FEAA3402-E101-4ABD-9337-BDEEFC6D29CAC815ACE8-3DBF-4FFD-8231-AB1D21E8B7EE
Loading...