Infection Channel: Dropped by other malware, Downloaded from the Internet
This adware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. It may be dropped by other malware.
It presents itself as a plugin/add-on/extension for certain applications.
File size: 57,856 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 01 Jun 2012
Arrival Details
This adware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It may be dropped by the following malware:
Installation
This adware drops the following files:
- %Application Data%\Google_Toolbar\Google_Toolbar\1.0.0.0\chrome\background.html
- %Application Data%\Google_Toolbar\Google_Toolbar\1.0.0.0\chrome\google.html
- %Application Data%\Google_Toolbar\Google_Toolbar\1.0.0.0\chrome\manifest.json
- %Application Data%\Google_Toolbar\Google_Toolbar\1.0.0.0\chrome.crx
- %Application Data%\Google_Toolbar\Google_Toolbar\1.0.0.0\chrome.manifest
- %Application Data%\Google_Toolbar\Google_Toolbar\1.0.0.0\chrome.pem
- %Application Data%\Google_Toolbar\Google_Toolbar\1.0.0.0\content
- %Application Data%\Google_Toolbar\Google_Toolbar\1.0.0.0\content\googlebar.js
- %Application Data%\Google_Toolbar\Google_Toolbar\1.0.0.0\content\googlebar.xul
- %Application Data%\Google_Toolbar\Google_Toolbar\1.0.0.0\install.rdf
- %Application Data%\Google_Toolbar\Google_Toolbar\1.0.0.0\MyGoogle.html
- %Application Data%\Mozilla\Firefox\Profiles\1o2kn33k.default\.autoreg
- %Application Data%\Mozilla\Firefox\Profiles\1o2kn33k.default\downloads.sqlite
- %Application Data%\Mozilla\Firefox\Profiles\1o2kn33k.default\bookmarkbackups\bookmarks-2012-06-05.json
(Note: %Application Data% is the current user's Application Data folder, which is usually C:\Windows\Profiles\{user name}\Application Data on Windows 98 and ME, C:\WINNT\Profiles\{user name}\Application Data on Windows NT, and C:\Documents and Settings\{user name}\Local Settings\Application Data on Windows 2000, XP, and Server 2003.)
It creates the following folders:
- %Application Data%\Google_Toolbar
- %Application Data%\Google_Toolbar\Google_Toolbar
- %Application Data%\Google_Toolbar\Google_Toolbar\1.0.0.0
- %Application Data%\Google_Toolbar\Google_Toolbar\1.0.0.0\chrome
(Note: %Application Data% is the current user's Application Data folder, which is usually C:\Windows\Profiles\{user name}\Application Data on Windows 98 and ME, C:\WINNT\Profiles\{user name}\Application Data on Windows NT, and C:\Documents and Settings\{user name}\Local Settings\Application Data on Windows 2000, XP, and Server 2003.)
Autostart Technique
This adware adds the following registry entries to install itself as a Browser Helper Object (BHO):
HKEY_CURRENT_USER\Software\Mozilla\
Firefox\Extensions
googlebar@google.com = "%Application Data%\Google_Toolbar\Google_Toolbar\1.0.0.0"
HKEY_CURRENT_USER\Software\Wow6432Node\
Mozilla\Firefox\Extensions
googlebar@google.com = "%Application Data%\Google_Toolbar\Google_Toolbar\1.0.0.0"
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Google\Chrome\Extensions\
fldnjidbmhkdbjmojbopclcjbjonnanb
path = "%Application Data%\Google_Toolbar\Google_Toolbar\1.0.0.0\chrome.crx"
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Google\Chrome\Extensions\
fldnjidbmhkdbjmojbopclcjbjonnanb
version = "1.0"
HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Chrome\Extensions\fldnjidbmhkdbjmojbopclcjbjonnanb
path = "%Application Data%\Google_Toolbar\Google_Toolbar\1.0.0.0\chrome.crx"
HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Chrome\Extensions\fldnjidbmhkdbjmojbopclcjbjonnanb
version = "1.0"
Other System Modifications
This adware adds the following registry keys as part of its installation routine:
HKEY_CURRENT_USER\Software\Mozilla
HKEY_CURRENT_USER\Software\Mozilla\
Firefox
HKEY_CURRENT_USER\Software\Mozilla\
Firefox\Extensions
HKEY_CURRENT_USER\Software\Wow6432Node
HKEY_CURRENT_USER\Software\Wow6432Node\
Mozilla
HKEY_CURRENT_USER\Software\Wow6432Node\
Mozilla\Firefox
HKEY_CURRENT_USER\Software\Wow6432Node\
Mozilla\Firefox\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Google
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Google\Chrome
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Google\Chrome\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Google\Chrome\Extensions\
fldnjidbmhkdbjmojbopclcjbjonnanb
HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Chrome
HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Chrome\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Google\
Chrome\Extensions\fldnjidbmhkdbjmojbopclcjbjonnanb
Other Details
This adware presents itself as a plugin/add-on/extension for the following applications:
Connect with us on
| | | |