Content
AdClicker-BA!D106701E
- Type
- Trojan
- SubType
- -
- Discovery Date
- 06/30/2008
- Length
- 150016
- Minimum DAT
- 5327 (06/27/2008)
- Updated DAT
- 5327 (06/27/2008)
- Minimum Engine
- 5.2.00
- Description Added
- 06/30/2008
- Description Modified
- 06/30/2008 3:27 AM (PT)
Tab Navigation
Characteristics
| File Property | Property Value |
|---|---|
| File Name | malign~1.exe |
| McAfee Detection | AdClicker-BA |
| Length | 150,016 bytes |
| CRC32 | D106701E |
| MD5 | 84c51570890b5a1c2c0a55ccf1b87324 |
| SHA1 | D7E845054282FD3142DFECD9BFA642686E7CE5CD |
Other Common Detection Aliases
| Company Name | Detection Name |
|---|---|
| AVG (GriSoft) | dropper.agent.5.ba |
| Microsoft | trojandropper:win32/agent.hz |
| Norman | w32/agent.hld |
| Panda | Trj/Downloader.MDW |
| Symantec | Trojan.Elitebar |
| Trend Micro | TROJ_STARTPAG.OV |
Avert® Labs has observed the following system activities:
| Activity | Risk Level |
|---|---|
| Modifies Memory of Other Processes | High |
| Enumerates running Processes | Medium |
| Attempts to Alter a Browsers User Agent | Low |
| Creates an Internet Explorer Tool Bar | Low |
| Creates Registry Keys and Data values persistent on OS Reboot | Low |
| Enumerates open windows | Low |
| Writes Executable in the Windows Folder | Low |
| Program often suspends itself | Informational |
| Registers DLLs | Informational |
System Changes
These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files
The following files have been added to the system:
The following registry elements have been created:
- ac = 48
- ad = 48
- at = 3158067
- i = {e74fcdec-85d6-4661-9a11-97b8cfed26c0}
- tm = 10
- tr = 1200
- u = 48
- (default) = &elitebar
- (default) = c:\windows\elitetoolbar\elitetoolbar version 60.dll
- threadingmodel = apartment
- (default) = &elitebar
- (default) = c:\windows\elitetoolbar\elitetoolbar version 60.dll
- threadingmodel = apartment
- _show = 1
- ac1 = adult
- accountnumber = malign~1
- adult.tbr = 48
- autocomplete = 1
- axparam = &cc=1
- default.tbr = 48
- firsttimestarted = 1
- guid = b5174e34-1b91-4695-a143-27e4941c1e36
- path = c:\windows\elitetoolbar\
- popupblocker = 26223
- popupblocker = no
- popups = 7562617
- pthreshold = 53
- search.mnu = 48
- searchindex = 0
- uninstalled = no
- updateattempt = 06080714
- updatedate = 010101
- version = 60
- displayicon = "c:\windows\elitetoolbar\elitetoolbar version 60.dll", 1
- displayname = elitebar internet explorer toolbar
- uninstallstring = regsvr32 /s /u "c:\windows\elitetoolbar\elitetoolbar
version 60.dll"
The following registry elements have been changed:
- programcount = 1
- programcount = 2
- {01e04581-4eee-11d0-bfe9-00aa005b4383} = [binary data]
- {0e5cbf21-d15f-11d0-8301-00aa005b4383} = [binary data]
- itbarlayout = [binary data]
- order = [binary data]
- (default) = c:\windows\system32\oleacc.dll
- (default) = oleacc.dll
- enable browser extensions = 7562617
- {825cf5bd-8862-4430-b771-0c15c5ca8def} = elitetoolbar
- etbrun = c:\windows\system32\elitexdk32.exe
- pendingfilerenameoperations = \??\c:\temp.exe
The applications created the following network connection(s):
- hxxp://[Domain Removed]/control.php?q
=96C7A8CAD796D8CA6E6A589BAD9D999E6A6E9896686A659A9F6D579DADCA9D96A2D398
C6CD72D2D4A598A7A79D985BC59E9BC4D99EAA8FDAC8AA6E665ECCB0AD9AD671918796C
8DA9DAD91A89AA672915FA8C8C5A49998C5D3A6A6736887ACA099C996C2D372D2D457A9
A1A4ADA472DA9EA889DA97A8A3CFD5A66E6C6887A8AA72BB9DCFB98589976189A4A39E9
9A8D4A2A4D1C59E5B62968B6A615C99C49C7482A580AAA883E296579C957165655BD6A7
9ED1D7A6979CD2CB9C6EA4A7879C9A7295&unique_user=b5174e34-1b91-4695-a143
-27e4941c1e36
- hxxp://sa.windows.com /sasearch/************
- hxxp://sa.windows.com /sasearch/*************
- hxxp://update.msupdater.com /***************************************
- hxxp://update.msupdater.com
/**********************************************************************
******************************
Symptoms
This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.
Method of Infection
Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, e-mail, etc.
Removal
AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.
Variants
Variants
N/A
All Information
Overview -
This is a Trojan detection. Unlike viruses, Trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include e-mail, malicious or hacked Web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.
Characteristics
Characteristics -
| File Property | Property Value |
|---|---|
| File Name | malign~1.exe |
| McAfee Detection | AdClicker-BA |
| Length | 150,016 bytes |
| CRC32 | D106701E |
| MD5 | 84c51570890b5a1c2c0a55ccf1b87324 |
| SHA1 | D7E845054282FD3142DFECD9BFA642686E7CE5CD |
Other Common Detection Aliases
| Company Name | Detection Name |
|---|---|
| AVG (GriSoft) | dropper.agent.5.ba |
| Microsoft | trojandropper:win32/agent.hz |
| Norman | w32/agent.hld |
| Panda | Trj/Downloader.MDW |
| Symantec | Trojan.Elitebar |
| Trend Micro | TROJ_STARTPAG.OV |
Avert® Labs has observed the following system activities:
| Activity | Risk Level |
|---|---|
| Modifies Memory of Other Processes | High |
| Enumerates running Processes | Medium |
| Attempts to Alter a Browsers User Agent | Low |
| Creates an Internet Explorer Tool Bar | Low |
| Creates Registry Keys and Data values persistent on OS Reboot | Low |
| Enumerates open windows | Low |
| Writes Executable in the Windows Folder | Low |
| Program often suspends itself | Informational |
| Registers DLLs | Informational |
System Changes
These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files
The following files have been added to the system:
The following registry elements have been created:
- ac = 48
- ad = 48
- at = 3158067
- i = {e74fcdec-85d6-4661-9a11-97b8cfed26c0}
- tm = 10
- tr = 1200
- u = 48
- (default) = &elitebar
- (default) = c:\windows\elitetoolbar\elitetoolbar version 60.dll
- threadingmodel = apartment
- (default) = &elitebar
- (default) = c:\windows\elitetoolbar\elitetoolbar version 60.dll
- threadingmodel = apartment
- _show = 1
- ac1 = adult
- accountnumber = malign~1
- adult.tbr = 48
- autocomplete = 1
- axparam = &cc=1
- default.tbr = 48
- firsttimestarted = 1
- guid = b5174e34-1b91-4695-a143-27e4941c1e36
- path = c:\windows\elitetoolbar\
- popupblocker = 26223
- popupblocker = no
- popups = 7562617
- pthreshold = 53
- search.mnu = 48
- searchindex = 0
- uninstalled = no
- updateattempt = 06080714
- updatedate = 010101
- version = 60
- displayicon = "c:\windows\elitetoolbar\elitetoolbar version 60.dll", 1
- displayname = elitebar internet explorer toolbar
- uninstallstring = regsvr32 /s /u "c:\windows\elitetoolbar\elitetoolbar
version 60.dll"
The following registry elements have been changed:
- programcount = 1
- programcount = 2
- {01e04581-4eee-11d0-bfe9-00aa005b4383} = [binary data]
- {0e5cbf21-d15f-11d0-8301-00aa005b4383} = [binary data]
- itbarlayout = [binary data]
- order = [binary data]
- (default) = c:\windows\system32\oleacc.dll
- (default) = oleacc.dll
- enable browser extensions = 7562617
- {825cf5bd-8862-4430-b771-0c15c5ca8def} = elitetoolbar
- etbrun = c:\windows\system32\elitexdk32.exe
- pendingfilerenameoperations = \??\c:\temp.exe
The applications created the following network connection(s):
- hxxp://[Domain Removed]/control.php?q
=96C7A8CAD796D8CA6E6A589BAD9D999E6A6E9896686A659A9F6D579DADCA9D96A2D398
C6CD72D2D4A598A7A79D985BC59E9BC4D99EAA8FDAC8AA6E665ECCB0AD9AD671918796C
8DA9DAD91A89AA672915FA8C8C5A49998C5D3A6A6736887ACA099C996C2D372D2D457A9
A1A4ADA472DA9EA889DA97A8A3CFD5A66E6C6887A8AA72BB9DCFB98589976189A4A39E9
9A8D4A2A4D1C59E5B62968B6A615C99C49C7482A580AAA883E296579C957165655BD6A7
9ED1D7A6979CD2CB9C6EA4A7879C9A7295&unique_user=b5174e34-1b91-4695-a143
-27e4941c1e36
- hxxp://sa.windows.com /sasearch/************
- hxxp://sa.windows.com /sasearch/*************
- hxxp://update.msupdater.com /***************************************
- hxxp://update.msupdater.com
/**********************************************************************
******************************
Symptoms
Symptoms -
This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.
Method of Infection
Method of Infection -
Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, e-mail, etc.
Removal -
Removal -
AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A