Symantec.com > Business > Security Response > Adware.IEPlugin

Adware.IEPlugin

Printer Friendly Page

Updated: 13 February 2007 11:37:42 AM
Type: Adware
Version: 1.0
Publisher: Not available
Risk Impact: High
File Names: Wupdt.exepxckdla.exe,wdskctl.exe,systb.dll,systb.exe,snbho.exe,winserv.exe,extract.exe,rgrt.exe,pa
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP

Behavior


Adware.IEPlugin is an Internet Explorer (IE) Browser Helper Object that monitors Web site addresses, content entered into forms, and local file names that are browsed.

Adware.IEPlugin displays an advertisement when it sees a targeted keyword. It will also install a running process to update itself by contacting servers every few minutes. This adware may also add bookmarks to the Favorites menu.

Note: LiveUpdate virus definitions, which were released on December 10, 2003, may erroneously trigger a detection of Backdoor.Imiserv on files that behave in a manner similar to the behavior of files detected as Adware.IEPlugin.

To correct this, virus definitions released on December 15, 2003 will detect such samples as Adware.IEPlugin.

Symptoms


The files are detected as Adware.IEPlugin.

Transmission


Active-X, drive-by downloads, which may be on pop-up ads, install this adware. There are also known programs that have Adware.IEPlugin inside of them and install it as the program itself is installed.

Protection

  • Initial Rapid Release version 20 May 2003
  • Latest Rapid Release version 21 November 2009 revision 020
  • Initial Daily Certified version 20 May 2003
  • Latest Daily Certified version 21 November 2009 revision 021
  • Initial Weekly Certified release date 22 May 2003

Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Symantec Client Security