Threat Database Adware Adware.Gator

Adware.Gator

By CagedTech in Adware
Published:
Last updated:

Threat Scorecard

Popularity Rank: 12,127
Threat Level: 20 % (Normal)
Infected Computers: 109
First Seen: July 24, 2009
Last Seen: September 14, 2026
OS(es) Affected: Windows

The detection of Adware.Gator on your system indicates the presence of unwanted software that may be displaying advertisements, collecting user data, or performing other potentially unwanted actions. This type of software can be frustrating and potentially harmful to your online security and privacy. In this removal report, we will provide guidance on what Adware.Gator is, how it operates, the symptoms of infection, and most importantly, how to remove it from your system.

What Is Adware.Gator?

Adware.Gator is a type of malicious software that is designed to display unwanted advertisements on an infected system. It can take many forms, including pop-up ads, banners, and sponsored links. Adware.Gator may also collect user data, such as browsing history and search queries, to deliver targeted advertisements. This type of software can be installed on a system without the user's knowledge or consent, often through bundling with other software or by exploiting vulnerabilities in the system.

How Adware.Gator Operates

Adware.Gator operates by installing itself on a system and then connecting to a remote server to download and display advertisements. It may also use various techniques to evade detection, such as code obfuscation and anti-debugging methods. Once installed, Adware.Gator can monitor user activity, collect data, and display unwanted advertisements. It may also install additional software or modify system settings to further compromise the system.

Symptoms of Infection

The symptoms of Adware.Gator infection can vary, but common signs include an increase in unwanted advertisements, slow system performance, and suspicious program installations. Users may also notice that their browser homepage or search engine has been changed without their consent. Additionally, Adware.Gator may cause system crashes, freezes, or other stability issues. If you are experiencing any of these symptoms, it is likely that your system is infected with Adware.Gator or other malicious software.

How to Remove Adware.Gator

  1. Boot your system in Safe Mode with Networking to prevent Adware.Gator from loading and to allow for a clean removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of Adware.Gator and other malicious software.
  3. Uninstall any suspicious programs or software that may be related to Adware.Gator. Be cautious when uninstalling programs, as some may be legitimate or required by the system.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any changes made by Adware.Gator.
  5. Reboot your system and perform another full scan to ensure that all remnants of Adware.Gator have been removed.

Conclusion

Removing Adware.Gator from your system requires a combination of technical knowledge and the right tools. By following the steps outlined in this removal report, you should be able to successfully remove Adware.Gator and restore your system to a clean and secure state. It is essential to remain vigilant and take proactive measures to prevent future infections, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious when downloading and installing software from the internet.

File System Details

Adware.Gator may create the following file(s):
# File Name MD5 Detections
1. DivXPro502GAINBundle.exe dc9c9a3d61ebb3a9feb49b3e04356e4b 42
2. CLADD a0595da9d68a9ad566ac3880ac4b7f62 0
More files

Analysis Report

General information

Family Name: Adware.Gator
Signature status: No Signature

Known Samples

MD5: 0ea78f231cf0a6bd947065745946381d
SHA1: 8d9c7f4d12b56c1ef7b2799e8b50a89857dce3c6
SHA256: 6F25A30891B08AF923044E63A437952C77A7E90B2D37CC7BC00B3521A77371ED
File Size: 283.17 KB, 283170 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
File Version 4.2.0.1
Original Filename Trickler.exe
Product Version 4.2.0.1

File Traits

  • x86

Block Information

Total Blocks: 993
Potentially Malicious Blocks: 539
Whitelisted Blocks: 453
Unknown Blocks: 1

Visual Map

x x x x x x x x x 0 x x x x x x 0 0 x 0 x x x x x 0 0 x x x x x x x 0 0 x 0 x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x 0 0 0 x x x x x x x x x x x 0 x x x 0 x x x x x x x x 0 0 x 0 x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x 0 ? x x x x x x x x 0 x x x x x x x x x 0 x x 0 0 x x 0 0 x x x 0 x x 0 x x x x x x 1 x x x x x x x x 0 0 0 x 0 x x x x 0 x x 0 0 x x x x 0 0 0 0 0 0 0 0 x x 0 0 0 0 x x 0 x x x 0 0 x x 0 0 x 0 0 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 x x x x x x x x x x x x x x x x x 0 x x x x x x x 0 x x x x x x x 0 x 0 x 0 x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 x x x x 0 x 1 x 0 x x x x x x x 0 x x x x x x x x 0 x x 0 x x x x 0 0 x x x x 0 x 0 x x x x x x 0 x x x x x 0 x 0 0 0 x x x x x x x x x x x x x x x x x x x x x 0 x x x x x 0 x x x x x 0 x x 0 0 x x x 0 x 0 x x x x x x x x x 0 x 0 x 0 0 x x 0 x x x x 0 x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x 0 x x x x x x x x x 0 x 0 x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 0 x x x x x x 1 x x x x x x x x x x x x x x x x x 0 0 x x x 0 x 1 x x 0 0 0 x x x x 0 x x x x 0 0 x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x 0 0 1 0 0 0 0 0 1 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 x 0 x x x x x x 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x 0 x 0 x 0 x 0 x 0 0 0 0 0 0 x x x x x 0 0 0 0 0 x x x x x x x x x x x x x 0 0 x x x x 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Gator.A

Registry Modifications

Key::Value Data API Name
HKLM\software\classes\wow6432node\clsid\{21ffb6c0-0da1-11d5-a9d5-00500413153c}::uets 偉쑪㌏⭑ RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{21ffb6c0-0da1-11d5-a9d5-00500413153c}::gef @ RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler::firststartvalue ͉ RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\gator\dyn::pdpfirststart 841:NEW RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
Show More
HKLM\software\wow6432node\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\ginternet\proxy::enabled RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\gator\stat::guid 1692DA31-0A72-459B-9AF9-9940557FC3B5 RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{21ffb6c0-0da1-11d5-a9d5-00500413153c}::gmg 1692DA31-0A72-459B-9AF9-9940557FC3B5 RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\silentsetup\dl::attempts RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\silentsetup\dl::errors RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\silentsetup\dl::filedones RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\silentsetup\dl::urltime RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\silentsetup\dl::urlsize ￿￿ RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\silentsetup\dl::storedfile RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\silentsetup\chk::checkfailures RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\silentsetup\chk::attempts RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\silentsetup\chk::errors RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\bundle\dl::attempts RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\bundle\dl::errors RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\bundle\dl::filedones RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\bundle\dl::urltime RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\bundle\dl::urlsize ￿￿ RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\bundle\dl::storedfile RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\bundle\chk::checkfailures RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\bundle\chk::attempts RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\bundle\chk::errors RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\oemresdll\dl::attempts RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\oemresdll\dl::errors RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\oemresdll\dl::filedones RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\oemresdll\dl::urltime RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\oemresdll\dl::urlsize ￿￿ RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\oemresdll\dl::storedfile RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\oemresdll\chk::checkfailures RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\oemresdll\chk::attempts RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler\files\oemresdll\chk::errors RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler::starttime 娟楰 RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\trickler::starttime 娟楰 RegNtPreCreateKey
HKLM\software\wow6432node\gator.com\gator\stat::guid 9136D7BB-7BB6-491A-80FD-4E1398D5F4C9 RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{21ffb6c0-0da1-11d5-a9d5-00500413153c}::gmg 9136D7BB-7BB6-491A-80FD-4E1398D5F4C9 RegNtPreCreateKey

Windows API Usage

Category API
Network Winsock2
  • WSAStartup
Network Wininet
  • InternetConnect
  • InternetOpen
  • InternetQueryOption
Network Winhttp
  • WinHttpOpen