Autumn Leaves (autumnleaves.exe)

Autumn Leaves (autumnleaves.exe) is an adware bundler that installs other adware with itself like Adware-GAIN (Claria). The Adware that it installs with itself may download and displays advertisements.

General information:

Malware Name: Autumn Leaves (autumnleaves.exe)
Malware Type: Adware Bundler
Company Name: Acez Software LLC
Company URL: http://www.acez.com/
Threat Level: Low Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

Acez Software LLC provides you the software Autumn Leaves (autumnleaves.exe) that shows you excellent image of autumn leaves with music.

Spyware Description:

Autumn Leaves (autumnleaves.exe) is an adware bundler that installs other adware with itself like Adware-GAIN (Claria). The Adware that it installs with itself may download and displays advertisements.

Characteristics/Symptoms:

    -> It installs other adware with itself like Adware-GAIN (Claria). -> The Adware that it installs with itself may download and displays advertisements.

Additional information might be found here:

google Search at Google for Autumn Leaves (autumnleaves.exe)
bing Search at Bing for Autumn Leaves (autumnleaves.exe)
yahoo Search at Yahoo for Autumn Leaves (autumnleaves.exe)

Processes Running:

Autumn Leaves.scr

File information Created after Installation:

File Location Size (Bytes) Type
C:\Documents and Settings\[USER]\Start Menu\Programs\iBoost\Uninstall Autumn Leaves.lnk 1560 Shortcut
C:\WINDOWS\Autumn Leaves.scr 1563767 Screen Saver
C:\WINDOWS\imgdll.dll 382464 Application Extension

Folder information Created after Installation:

Folder Location
C:\Documents and Settings\[USER]\Start Menu\Programs\iBoos
C:\WINDOWS\iGato

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE \SOFTWARE\Gator.com\Gator\dyn\Proxy UsingWininet
HKEY_LOCAL_MACHINE \SOFTWARE\Gator.com\Trickler
HKEY_LOCAL_MACHINE \SOFTWARE\Gator.com\Trickler\EventCache\47188B8A.0002