Threat Database Adware Adware.Gabpath

Adware.Gabpath

By GoldSparrow in Adware

Threat Scorecard

Popularity Rank: 22,011
Threat Level: 20 % (Normal)
Infected Computers: 1,570
First Seen: November 30, 2010
Last Seen: December 12, 2025
OS(es) Affected: Windows

Adware.Gabpath is a malicious adware parasite that could unknowingly be installed on a PC. After it is installed, Adware.Gabpath may display several misleading alert messages that can become very annoying. Adware.Gabpath has been known to lead to the redirection to dangerous third party websites that may download malware. Adware.Gabpath may easily be removed with the use of a reputable spyware removal application.

Aliases

15 security vendors flagged this file as malicious.

Antivirus Vendor Detection
AVG Generic4.AIUQ
AntiVir TR/Dldr.Agent.dwxx
Kaspersky Trojan-Downloader.Win32.Agent.dwxx
McAfee Artemis!8ACE4599C497
AntiVir Adware/Gabpath.A.1266
Kaspersky Trojan.Win32.Gabba.dhl
AntiVir Adware/Gabpath.A.2667
Kaspersky not-a-virus:AdWare.Win32.Gaba.gfs
eSafe Win32.Trojan
Avast Win32:Gabpath-EW
McAfee Artemis!D352E363B148
AntiVir Adware/GabPath.S.34
McAfee Artemis!6344F23D3C82
AntiVir TR/Graftor.48688.12
Kaspersky Trojan.Win32.FakeAV.oaid

SpyHunter Detects & Remove Adware.Gabpath

File System Details

Adware.Gabpath may create the following file(s):
# File Name MD5 Detections
1. Blammi.exe 61c092484bd2284f84ff5fa15da75500 123
2. minoral.exe c43e87365d142f7d0a023bc82800c00c 14
3. oulwsvm.exe 73377916de2934cb21e2e918fbb526e9 13
4. ryndehhg.exe 3d3e1fcc18b65debd836ef95f5ab29ac 8
5. fatkidb.exe 5394e1e4313881b5eb7b0ecf065462d9 4
6. hlublwe.exe edebc8f248bccd6de422715eb5231619 4
7. bcfiugj.exe bc486977a42b54b47a5256d863a9432d 4
8. efogwqla.exe ff5ebcd630e69d690c31d4dd8b62ef7c 3
9. lqginlcsi.exe 239138e74f55d5b3114c3d07b7a09873 3
10. ylmduet.exe 9d37db054b013a9fcc066c64da3f04ad 2
11. mtjmlhm.exe 66768e2d5c5ce3eb860fd7a2afca287d 2
12. egwegip.exe 3b9e761ec8022eb2a786f3b16e299bed 2
13. prcrnns.exe 225902081f9f3cedbd71be5531fafadd 2
14. pcwkyaukg.exe 1414ab3b615eb9b5f04887344629e66d 2
15. iabnjr.exe 5acb6d5d6e21c8bbf905e7e656c07c64 2
16. rkopud.exe 51a752a3484f05f9b8bd374d1ef1ca03 2
17. AdvService.exe 83d5c5bef22d644fcbe4af7704b30a3c 2
18. ctkseftv.exe deba3d81e91be9335f5da0e39a546023 1
19. uawesqdx.exe 2f11b75f018e56e6b2800dd4c0d95005 1
20. crgrsf.exe 58b76caaea517d49af7698ddd4353804 1
21. nsaEBBA.exe 54d6a0de212865fe927eacf4347c380c 1
22. eiqcocu.exe 7a4d2c897877c269d147d04c7c8abc4d 1
23. 4778.dll 23126d1e6f6f9c00f9b2985d3e2d6a3e 1
24. nseB7.exe 255260fd20518b8ff9b7eae942b838ea 1
25. wheresphere.exe 3eabf58796dc856b4da74b7412da7a67 1
26. GabPath.exe d352e363b14817246f5f544afe3fe8ee 1
27. hdysvu.exe 9f4947630f5461ada5643a225cc6e7a6 1
More files

Analysis Report

General information

Family Name: Adware.Gabpath
Signature status: No Signature

Known Samples

MD5: 1180a9e9d43cd1ca72f3aad8eb412011
SHA1: 39764611fc2658b28269e77c72e5494beba5923d
SHA256: 6C636BAE4F28AE7C07251970195616CB69BAAB29341CDCFCDA4AD0CC4F28B7EE
File Size: 286.72 KB, 286720 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 980
Potentially Malicious Blocks: 2
Whitelisted Blocks: 935
Unknown Blocks: 43

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 1 1 3 0 1 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 2 3 0 0 0 0 0 0 0 0 0 1 1 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 x ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\run::gabpath C:\Users\Xublkkrw\AppData\Roaming\GabPath\gabpath.exe RegNtPreCreateKey
HKLM\software\wow6432node\mozilla\firefox\extensions::{4bcdbfd0-fa26-11de-8a39-0800200c9a66} C:\Users\Xublkkrw\AppData\Roaming\Mozilla\FireFox\{4bcdbfd0-fa26-11de-8a39-0800200c9a66} RegNtPreCreateKey

Windows API Usage

Category API
Other Suspicious
  • SetWindowsHookEx
Network Winsock2
  • WSAStartup
Network Winsock
  • gethostbyname
  • inet_addr
  • socket

Related Posts

Trending

Most Viewed

Loading...