SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Adgazelle.A_4
Adgazelle.A_4 is an Adware. Adware, or advertising-supported software, is any software that automatically renders advertisements in order to generate revenue for its author. The advertisements may be in the user interface of the software or on a screen presented to the user during the installation process. It is usually annoying but harmless, unless it is combined with spyware or trackware.

File Related Changes
It drops the following file(s) on the system:
  • "C:\Program Files\Youdao\ShoppingAssistant\ie\3.10\CrashRpt.dll"
  • "C:\Program Files\Youdao\ShoppingAssistant\ie\3.10\YoudaoAssistant.dll"

Process Related Changes
It creates the following mutex(es):
  • ZonesCacheCounterMutex"
  • _!MSFTHISTORY!_"
  • ZonesLockedCacheCounterMutex"
  • WininetConnectionMutex"
  • c:!users!admin!appdata!roaming!microsoft!windows!ietldcache!"
  • ZonesCounterMutex"
  • ZoneAttributeCacheCounterMutex"
  • RasPbFile"
  • c:!users!admin!appdata!local!microsoft!windows!history!history.ie5!"
  • c:!users!admin!appdata!local!microsoft!windows!temporary internet files!content.ie5!"
  • c:!users!admin!appdata!roaming!microsoft!windows!cookies!"
  • IESQMMUTEX_0_208"
  • WininetProxyRegistryMutex"
  • GouwuZhushouProfileSharedMemeorymutext"
  • WininetStartupMutex"
  • !IETld!Mutex"

It creates the following process(es):
  • c:\Program Files\Youdao\ShoppingAssistant\ie\3.10\InstallAssistant.exe [ \c:\Program Files\Youdao\ShoppingAssistant\ie\3.10\InstallAssistant.exe /vendor:silent8 /P \c:\Program Files\Youdao\ShoppingAssistant\ie\3.10 /S ]

Network Activity
We observed the following DNS query/queries:
  • a.youdao.com
  • zhushou.huihui.cn
  • wpad


Relevant Information