Content

AdClicker-GF

Type
Trojan
SubType
Generic
Discovery Date
07/09/2008
Length
varies
Minimum DAT
5335 (07/09/2008)
Updated DAT
5337 (07/11/2008)
Minimum Engine
5.1.00
Description Added
07/09/2008
Description Modified
07/17/2008 2:44 AM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

This detection is for an AdClicker trojan.

This detection is for a "dll" file.

This "dll" file exports functions that can be used by other programs to display Feeds with random search engines.

This may also be used to display ADs while browsing the internet.

Symptoms

Presence of Feeds which redirect to different search engine websites.

Method of Infection

Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, email, etc.

Removal

AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.

Additional Windows ME/XP removal considerations

Variants

Variants

    N/A

All Information

Overview -

This detection is for an AdClicker trojan.

Aliases

  • Trj/Clicker.ALI (Panda)
  • Trojan-Clicker.Win32.Small.zg (Kaspersky)
  • TrojanClicker:Win32/Zirit.Y (Microsoft)

Characteristics

Characteristics -

This detection is for an AdClicker trojan.

This detection is for a "dll" file.

This "dll" file exports functions that can be used by other programs to display Feeds with random search engines.

This may also be used to display ADs while browsing the internet.

Symptoms

Symptoms -

Presence of Feeds which redirect to different search engine websites.

Method of Infection

Method of Infection -

Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, email, etc.

Removal -

Removal -

AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.

Additional Windows ME/XP removal considerations

Variants

Variants -

    N/A