Content

Uploader-R

Type
Program
SubType
Adware
Discovery Date
08/14/2004
Minimum DAT
4387 (08/18/2004)
Updated DAT
4874 (10/16/2006)
Minimum Engine
5.1.00
Description Added
08/18/2004
Description Modified
09/08/2004 11:55 AM (PT)

Tab Navigation

Characteristics

This is not a virus or trojan. It is a direct-marketing adware application.

This kind of application generally comes bundled with another program, which usually discloses the fact that it is ad-supported.  Users agree to have the Adware installed in the license agreement, although they may not realise at first that this file was packaged with the product they installed.

The program comes with a dropper file.  When the dropper runs,  the program is copied as the following file:

  • c:\Program Files\Common Files\tsa\tsl.exe

The following Registry key is added to hook system startup:

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    "Tsl" = "c:\Program Files\Common Files\tsa\tsl.exe"

The program connects to a specific web site.  It can further download other programs to the machine.  It might also post machine related information to the website.

Users who would like to check for the presence of potentially unwanted programs on their system should run the command line scanner with the /PROGRAM switch.
Please note that VirusScan 7, and higher, has an option that enables users to detect this kind of program automatically (see below).

Aliases

Aliases

  • Adware/Sqwire (Panda)
  • TrojanDownloader.Win32.TSUpdate.a (AVP)