Content

Adware-TopMoxie

Type
Program
SubType
Adware
Discovery Date
12/09/2003
Minimum DAT
4056 (12/15/1999)
Updated DAT
5983 (05/15/2010)
Minimum Engine
5.1.00
Description Added
01/06/2004
Description Modified
03/25/2004 10:47 PM (PT)

Tab Navigation

Characteristics

This is not a virus or trojan. It is a direct-marketing adware application. This application generates extra pop-up ads while using Internet Explorer.

This kind of application generally comes bundled with another program, which usually discloses the fact that it is ad-supported.  Users agree to have the Adware installed in the license agreement, although they may not realise at first that this file was packaged with the product they installed.

Installation

Upon execution, the application creates directory under C:\Program Files\.  Directory name varies depending on the programs it bundles with.  The following directory names have been used:

  • couponsandoffers
  • EbatesMoeMoneyMaker

It creates subdirectories and copies its program files there.  The following files are dropped:

  • couponsandoffers.exe
  • couponsandoffers1.exe

Or

  • EbatesMoeMoneyMaker.exe
  • EbatesMoeMoneyMaker1.exe

The following registry keys are created to load the application at Windows start up:

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "couponsandoffers" = "wjview /cp:p..."

Or

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "EbatesMoeMoneyMaker" = "wjview /cp:p..."

The application opens several ports on the local machine.  The application can be removed from the "Add/Remove Programs" from the Control Panel.

Users who would like to check for the presence of potentially unwanted programs on their system should run the command line scanner with the /PROGRAM switch.
Please note that VirusScan 7, and higher, has an option that enables users to detect this kind of program automatically (see below).

Aliases

Aliases

    N/A