1. Symantec-Broadcom-Horizontal/
  2. Security Response/
  3. Attack Signatures/
  4. System Infected: Adware.Adgoblin Activity

System Infected: Adware.Adgoblin Activity

Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

Description

This signature detects Adware.AdGoblin communicating and requesting information from its controlling server.

Additional Information

Adware.AdGoblin is an adware component that displays pop-up windows in Internet Explorer.

Adware :
Programs that facilitate delivery of advertising content to the user through their own window, or by utilizing another program's interface. In some cases, these programs may gather information from the user's computer, including information related to Internet browser usage or other computing habits, and relay this information back to a remote computer or other location in cyber-space.

Adware can be downloaded from Web sites (typically in shareware or freeware), email messages, and instant messengers. Additionally, a user may unknowingly receive and/or trigger adware by accepting an End User License Agreement from a software program linked to the adware or from visiting a website that downloads the adware with or without an End User License Agreement

Affected

  • Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP

Response

This adware program must be manually installed. However, there are several known programs that have Adware.AdGoblin within them and that install it as the program itself is installed.

Note: Removing this adware component from the system will likely cause the program that installed it to not function as intended. The uninstaller generally identifies the programs that will not work after uninstallation.

The following instructions pertain to all Symantec antivirus products that support the security risk detection.

1. Update the definitions.
2. Closing all the open Internet Explorer windows.
3. Run a full system scan and write down the locations of the files detected as Adware.AdGoblin
4. Uninstall Adware.AdGoblin using regsvr32.
5. Run a full system scan and delete all the files detected as Adware.AdGoblin.

Additional References

  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube