This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.
This signature detects Adware TopAV communicating and requesting information from its controlling server.
Adware.TopAV replaces the Windows wallpaper with a wallpaper displaying fake virus alert message containing links to the topantivirus.biz domain.
Programs that facilitate delivery of advertising content to the user through their own window, or by utilizing another program's interface. In some cases, these programs may gather information from the user's computer, including information related to Internet browser usage or other computing habits, and relay this information back to a remote computer or other location in cyber-space.
Adware can be downloaded from Web sites (typically in shareware or freeware), email messages, and instant messengers. Additionally, a user may unknowingly receive and/or trigger adware by accepting an End User License Agreement from a software program linked to the adware or from visiting a website that downloads the adware with or without an End User License Agreement
- Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
Note: Depending on how this hacktool was installed, it may be able to be uninstalled via the Add/Remove Programs applet in the control panel. Please try this first, followed by a complete scan (Steps 2/3). If there is no uninstall option in the Add/Remove Programs control panel, please continue with step 1.
1. Update the definitions.
2. Uninstall Adware.TopAV using the Add/Remove Programs utility.
3. Run a full system scan.
4. Delete any values added to the registry.
5. Reset the Desktop Background.