Home Malware Programs Potentially Unwanted Programs (PUPs) Gerbillio


Posted: April 24, 2014

Threat Metric

Threat Level: 2/10
Infected PCs: 98
First Seen: April 25, 2014
Last Seen: September 13, 2022
OS(es) Affected: Windows

Gerbillio is a potentially unwanted program (PUP)/adware that may urge PC users to use its software services by trying to attract computer users with the slogan 'Search smarter with Gerbillio'. At first glance, Gerbillio may look like a helpful tool but, in reality, it may be an annoying application. Once installed, Gerbillio may generate and show unwanted pop-up, in-text, search and other type advertisements and commercial messages on a PC carrying the 'Start Now!' button. If the PC user clicks the button, he may unknowingly allow to download and install other threats on the computer. Gerbillio may reroute computer users to sponsored websites that were designed possibly for commercial purposes. Gerbillio might be created with the aim to benefit from raised web traffic and ad clicks. Gerbillio may propagate and install itself onto the PC as an additional program packaged with free applications that computer users download and install from download websites. Gerbillio may insert an unwanted browser extension, plug-in or add-on in Web browsers such as Internet Explorer, Google Chrome, Mozilla Firefox and other popular Web browsers.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{F5D62360-C51E-4250-A6AA-C816DFC639F0}

Additional Information

The following directories were created:
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\ceglgjpdhjbkgaoajfhfchmedafkdbnn%LOCALAPPDATA%\Google\Chrome\User Data\Default\Local Extension Settings\ceglgjpdhjbkgaoajfhfchmedafkdbnn%LOCALAPPDATA%\Google\Chrome\User Data\Default\databases\chrome-extension_ceglgjpdhjbkgaoajfhfchmedafkdbnn_0%PROGRAMFILES%\gerbillio%PROGRAMFILES(x86)%\gerbillio
The following URL's were detected: