Home Malware Programs Adware FraLimbo

FraLimbo

Posted: February 3, 2014

Threat Metric

Threat Level: 2/10
Infected PCs: 227
First Seen: February 3, 2014
Last Seen: April 17, 2023
OS(es) Affected: Windows


FraLimbo is adware, which may target both a computer system and a Web browser and display unwanted pop-up advertisements and messages. FraLimbo may usually be distributed and enter the PC through bundled free programs that computer users can download from suspicious download websites on the Internet. When installed on the computer, FraLimbo may cover the PC with random pop-up ads, offers, discount coupons and deals or ads, deals and offers related to the PC user's browsing activities. FraLimbo may collect the computer user's surfing details and transmit and use them for the purpose of targeted marketing. FraLimbo may also lead to constant browser diversions to questionable websites that may be commercial and designed to possibly boost website traffic and make a profit from clicks on advertisements. FraLimbo may take over all the Web browsers installed on the computer system and make changes to the default browser settings.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES(x86)%\Fralimbo\bin\Fralimbo.BrowserAdapter.exe File name: Fralimbo.BrowserAdapter.exe
Size: 95.52 KB (95520 bytes)
MD5: 325ca310de97e6f13f7de35f92172737
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Fralimbo\bin
Group: Malware file
Last Updated: April 30, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{5dbf8f55-71ed-4e0e-8e34-7a5ef1183176}HKEY..\..\..\..{RegistryKeys}SOFTWARE\FralimboSoftware\Microsoft\Internet Explorer\Approved Extensions\{5DBF8F55-71ED-4E0E-8E34-7A5EF1183176}Software\Microsoft\Internet Explorer\Approved Extensions\{E829E35B-480B-45BF-8494-1BFC8257C5DA}SOFTWARE\Microsoft\Tracing\Fralimbo_RASAPI32SOFTWARE\Microsoft\Tracing\Fralimbo_RASMANCSSOFTWARE\Microsoft\Tracing\updateFralimbo_RASAPI32SOFTWARE\Microsoft\Tracing\updateFralimbo_RASMANCSSoftware\Microsoft\Windows\CurrentVersion\Ext\Settings\{5DBF8F55-71ED-4E0E-8E34-7A5EF1183176}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5DBF8F55-71ED-4E0E-8E34-7A5EF1183176}SOFTWARE\Wow6432Node\FralimboSOFTWARE\Wow6432Node\Microsoft\Tracing\Fralimbo_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\Fralimbo_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\updateFralimbo_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateFralimbo_RASMANCSSYSTEM\ControlSet001\services\eventlog\Application\Update FralimboSYSTEM\CurrentControlSet\services\eventlog\Application\Update Fralimbo

Additional Information

The following directories were created:
%PROGRAMFILES%\Fralimbo%PROGRAMFILES(x86)%\Fralimbo
Loading...