Home Malware Programs Spyware Timesink

Timesink

Posted: March 28, 2006

This pesky little application is used by many Internet advertising networks and its primary objective is to collect personal data about the user. It also causes browser pop-ups and shows ads. The application has no uninstall function, so if you want to get rid of it, you have to do it manually. The distributors of this application have formed strategic partnerships with many Internet advertising companies, so this malware is very popular. This newer version of ConducentTimesink was created in July 2002.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 ctchanconfig.dll
    2 ctinstall.exe
    3 flexactv.dll
    4 flexpakuninst.exe
    5 simpleregistration.dll
    6 tsad.dll
    7 tsadbot.exe
    8 tschannelconfig.exe
    9 tsuninstaller.exe
    10 vcpdll.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOTflexactive.flexactiveHKEY_CLASSES_ROOTflexactive.flexactive.1HKEY_CURRENT_USERsoftwareimesinkinc.HKEY_LOCAL_MACHINEsoftwareconducentHKEY_LOCAL_MACHINEsoftwareimesinkinc.HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionshareddllsc:windowsflexactv.dllHKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionshareddllsc:winntflexactv.dllHKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionuninstallflexpakHKEY_USERS.defaultsoftwareimesink
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}1dc1fa50-773d-11d3-9f9f-006097a7311b572a659c-37c9-11d4-b552-00c04f797b691dc1fa5d-773d-11d3-9f9f-006097a7311b1dc1fa5e-773d-11d3-9f9f-006097a7311b

Related Posts

Loading...