Content

Adware-Findemnow

Type
Program
SubType
Adware
Discovery Date
03/12/2004
Minimum DAT
4339 (03/17/2004)
Updated DAT
4589 (09/23/2005)
Minimum Engine
5.1.00
Description Added
03/12/2004
Description Modified
03/15/2004 4:01 PM (PT)

Tab Navigation

Characteristics

This program is detected as a "potentially unwanted application".

Detection was added to cover for an arguable file called "msxmlpp.dll " , having a filesize of 35328 bytes (decimal). The file is wriiten in MS-Visual C++ and it is internally compressed with upx.

The .dll file is usually dropped by other adware binary files. It has references to a commercial search site having the IP address 213.159.117.235. Apart from changing the Internet Explorer startup page and adding favorites, it also changes the drivers\etc\hosts file so that whenever a user searches for something on msn.com it gets redirected to the webpage from the adware.

The detection of this type of file is not automatically activated. Users who would like to check for the presence of this kind of files on their system should run the command line scanner with the /PROGRAM switch.
Please note that VirusScan 7 has also an option, which enables users to detect this kind of program automatically (see below).

Aliases

Aliases

    N/A