Content

Adware-eUniverse.dr

Type
Program
SubType
Dropper
Discovery Date
09/14/2005
Minimum DAT
4581 (09/14/2005)
Updated DAT
4667 (01/04/2006)
Minimum Engine
5.1.00
Description Added
09/14/2005
Description Modified
09/16/2005 5:23 AM (PT)

Tab Navigation

Characteristics

McAfee(R) AVERT(tm) recognizes that this program may have legitimate uses in contexts where an authorized administrator has knowingly installed this application. If you agreed to a license agreement for this, or another bundled application, you may have legal obligations with regard to removing this software, or using the host application without this software. Please contact the software vendor for further information.

See http://vil.nai.com/vil/DATReadme.asp for a list of Program detections added to the DATs.

See http://vil.nai.com/vil/pups/configuration.htm for information about how to enable, disable, and exclude detection of legitimately installed programs.

This is not a virus or a Trojan. It is an adware application.

Installation:

File:   SETUP_INCREDIFIND_CURSORS_WITH_TRACK.EXE
Hash: f9544e19d72373bf4fc601032d2eba35

Upon installation of this adware application the following changes occur in the user's system.

The following files are added:

  • BHO.dll
  • tipb.exe

BHO.dll is is installed as Browser Helper Object.

Browser Helper Objects are executable files that are loaded when the browser is launched. They can perform various task,such as generating extra pop-up ads, monitoring page navigation, etc.

The following Registry keys are added:

  • HKEY_CLASSES_ROOT\BHO.eUnivBHO
  • HKEY_LOCAL_MACHINE\SOFTWARE\eUniverse\BHO\HomePage
  • HKEY_LOCAL_MACHINE\SOFTWARE\eUniverse\BHO\RedirectURLS

This adware application is an Error Page Hijacker.
Error Page Hijacker is an application which resets internet explorer’s settings to displays a new error page when the requested URL is not found.



Aliases

Aliases

    N/A