Content

Tool-IdleUI

Type
Program
SubType
Tool
Discovery Date
10/13/2004
Minimum DAT
4398 (10/13/2004)
Updated DAT
4669 (01/06/2006)
Minimum Engine
5.1.00
Description Added
10/13/2004
Description Modified
10/18/2004 5:47 AM (PT)

Tab Navigation

Characteristics

This detection is of application type for "potentially unwanted applications". It is not a virus nor a trojan.

Users who would like to check for the presence of this program on their system should run the command line scanner with the /PROGRAM switch. Please note that VirusScan 7 and higher has an option, which enables users to detect this kind of program automatically.

Detection was added to cover for an arguable file originally called "idleui.dll " , having a filesize of 41472 bytes.  The file's purpose is to handle time events. When there is no gui activity for some time it initializes and may start calling other file's routines such as sending out captured user information for example.

This file is being used in adware packages, arguable commercial applications, but the file has also been used together with trojan files. An example is the PWS-Idly password stealing trojan, more information about that can be found here: http://vil.nai.com/vil/content/v_99900.htm

Aliases

Aliases

  • TR/Stomcc.5 (H+BEDV)
  • Trj/Idly.A (Panda)
  • TROJ_IDLY.C (Trend)
  • Trojan.Idly (Dialogue Science)
  • Trojan.Spy.Idly.C (Softwin)
  • TrojanSpy.Win32.Idly.c (Kaspersky)
  • W32/2ndThought (Norman)