Gator

By CagedTech in Adware

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 77
First Seen: January 3, 2013
Last Seen: December 26, 2022
OS(es) Affected: Windows

SpyHunter Detects & Remove Gator

Registry Details

Gator may create the following registry entry or registry entries:
SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Trickler
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Trickler

Analysis Report

General information

Family Name: Gator
Signature status: No Signature

Known Samples

MD5: 3956b5f489b5d153ef3317c3bd337056
SHA1: b8f0e68cc39eb2f18fd83d00cab032e3f419b3ab
SHA256: 19C8FBC49B7E74FAB426B48DD88D9DA14783AE1BDB8926810FAF5CA8570396F9
File Size: 3.83 MB, 3829760 bytes
MD5: 970b8c401cb5e61fd00a4f1cd5915e88
SHA1: d0ed8300d7e43a75c52ec69472b1e9846f626b3d
SHA256: 022E4C7AD1F4D26E4481D4C730FEFF6BB46DE74184B3A1C566997AE5C17744B1
File Size: 5.78 MB, 5783552 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 179
Potentially Malicious Blocks: 0
Whitelisted Blocks: 179
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Autorun.FA

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~vis0000\default.bmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~vis0000\default.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~vis0000\divx pro bundle.log Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~vis0000\divxplayerinstaller.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~vis0000\divxplayerinstaller.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~vis0000\divxplayerinstaller.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\~vis0000\divxpro_gain.jpg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~vis0000\divxpro_gain.jpg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~vis0000\divxvideocommondecode.reg Generic Read,Write Data,Write Attributes,Write extended,Append data
Show More
c:\users\user\appdata\local\temp\~vis0000\divxvideocommondecode.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~vis0000\divxvideocommondecode.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\~vis0000\divxvideocommonencode.reg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~vis0000\divxvideocommonencode.reg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~vis0000\divxvideocommonencode.reg Synchronize,Write Attributes
c:\users\user\appdata\local\temp\~vis0000\english.vlg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~vis0000\english.vlg Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~vis0000\gain banner.bmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~vis0000\gain banner.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~vis0000\gain.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~vis0000\gain.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~vis0000\gain.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\~vis0000\installer_splash_pro.gif Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~vis0000\installer_splash_pro.gif Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~vis0000\installerlicense Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~vis0000\installerlicense Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~vis0000\installerlicense Synchronize,Write Attributes
c:\users\user\appdata\local\temp\~vis0000\installrunner.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~vis0000\installrunner.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~vis0000\installrunner.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\~vis0000\jpeg.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~vis0000\jpeg.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~vis0000\miscdata.xyz Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~vis0000\miscdata.xyz Synchronize,Write Attributes
c:\users\user\appdata\local\temp\~vis0000\rebootnt.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~vis0000\rebootnt.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~vis0000\rollback.log Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~vis0000\uninst32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~vis0000\uninst32.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~vis0000\vise32ex.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~vis0000\vise32ex.dll Generic Write,Read Attributes

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Process Manipulation Evasion
  • ReadProcessMemory
Service Control
  • OpenSCManager

Related Posts

Trending

Most Viewed

Loading...