Content
AdClicker-ER
- Type
- Trojan
- SubType
- Win32
- Discovery Date
- 10/30/2006
- Length
- Varies
- Minimum DAT
- 4884 (10/30/2006)
- Updated DAT
- 6546 (11/30/2011)
- Minimum Engine
- 5.1.00
- Description Added
- 10/30/2006
- Description Modified
- 02/15/2007 10:53 PM (PT)
Tab Navigation
Characteristics
Variants of this trojans are designed to connect to the author's designated websites and redirect or pop-up banner advertisements. This is designed to make the trojan author money from a "click per view" scheme.
Silent Execution
This trojan installs a randomly named .SYS file and injects a hidden thread into the running Windows Explorer process (Explorer.exe). Network connections can then be spoofed to be coming from Explorer.exe. It contacts the following advertising site(s) silently without prompting:
- {blocked}.sodui.com/{blocked}/{blocked}.php
Dynamic Downloads
It may also download a list of files to install further updates, PUPs or malware from:
- {hidden}.newweb.com.cn
Symptoms
Presence of one or more of the following file(s) and folder(s):
- %Windir%\System32\winup (folder)
- %Windir%\System32\{XXXXYY}.sys (AdClicker-ER)
- %Windir%\System32\{XXXXYY}.dll (AdClicker-ER)
(Where XXXX are random alphabets from A-Z, and YY is a random number)
Presence of one or more of the following Windows Registry key(s):
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SSearch
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{XXXXXXYY}
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{XXXXXXYY}
(Where {XXXXXXYY} is the random filename installed by AdClicker-ER)
Unexpected HTTP connections periodically made by Windows Explorer (Explorer.exe) to the following IP address(es):
- 219.232.xx.xx
Method of Infection
They may be downloaded by other viruses and/or Trojans to be installed on the user's system. Many of these additionally can be mass spammed by the author to entice people into double-clicking on them.
Removal
All Users:
Please use the following instructions for all supported versions of Windows to remove threats and other potential risks:
2.Update to current engine and DAT files for detection and removal.
3.Run a complete system scan.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
1. Please go to the Microsoft Recovery Console and restore a clean MBR.
On windows XP:
Insert the Windows XP CD into the CD-ROM drive and restart the computer.
When the "Welcome to Setup" screen appears, press R to start the Recovery Console.
Select the Windows installation that is compromised and provide the administrator password
Issue 'fixmbr' command to restore the Master Boot Record
Follow onscreen instructions
Reset and remove the CD from CD-ROM drive.
On Windows Vista and 7:
Insert the Windows CD into the CD-ROM drive and restart the computer.
Click on "Repair Your Computer"
When the System Recovery Options dialog comes up, choose the Command Prompt.
Issue 'bootrec /fixmbr' command to restore the Master Boot Record
Follow onscreen instructions
Reset and remove the CD from CD-ROM drive.
Variants
Variants
N/A
All Information
Overview -
Variants of this trojans are designed to connect to the author's designated websites and redirect or pop-up banner advertisements. This is designed to make the trojan author money from a "click per view" scheme.
Characteristics
Characteristics -
Variants of this trojans are designed to connect to the author's designated websites and redirect or pop-up banner advertisements. This is designed to make the trojan author money from a "click per view" scheme.
Silent Execution
This trojan installs a randomly named .SYS file and injects a hidden thread into the running Windows Explorer process (Explorer.exe). Network connections can then be spoofed to be coming from Explorer.exe. It contacts the following advertising site(s) silently without prompting:
- {blocked}.sodui.com/{blocked}/{blocked}.php
Dynamic Downloads
It may also download a list of files to install further updates, PUPs or malware from:
- {hidden}.newweb.com.cn
Symptoms
Symptoms -
Presence of one or more of the following file(s) and folder(s):
- %Windir%\System32\winup (folder)
- %Windir%\System32\{XXXXYY}.sys (AdClicker-ER)
- %Windir%\System32\{XXXXYY}.dll (AdClicker-ER)
(Where XXXX are random alphabets from A-Z, and YY is a random number)
Presence of one or more of the following Windows Registry key(s):
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SSearch
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{XXXXXXYY}
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{XXXXXXYY}
(Where {XXXXXXYY} is the random filename installed by AdClicker-ER)
Unexpected HTTP connections periodically made by Windows Explorer (Explorer.exe) to the following IP address(es):
- 219.232.xx.xx
Method of Infection
Method of Infection -
They may be downloaded by other viruses and/or Trojans to be installed on the user's system. Many of these additionally can be mass spammed by the author to entice people into double-clicking on them.
Removal -
Removal -
All Users:
Please use the following instructions for all supported versions of Windows to remove threats and other potential risks:
2.Update to current engine and DAT files for detection and removal.
3.Run a complete system scan.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
1. Please go to the Microsoft Recovery Console and restore a clean MBR.
On windows XP:
Insert the Windows XP CD into the CD-ROM drive and restart the computer.
When the "Welcome to Setup" screen appears, press R to start the Recovery Console.
Select the Windows installation that is compromised and provide the administrator password
Issue 'fixmbr' command to restore the Master Boot Record
Follow onscreen instructions
Reset and remove the CD from CD-ROM drive.
On Windows Vista and 7:
Insert the Windows CD into the CD-ROM drive and restart the computer.
Click on "Repair Your Computer"
When the System Recovery Options dialog comes up, choose the Command Prompt.
Issue 'bootrec /fixmbr' command to restore the Master Boot Record
Follow onscreen instructions
Reset and remove the CD from CD-ROM drive.
Variants
Variants -
N/A