1. Symantec-Broadcom-Horizontal/
  2. Security Response/
  3. Attack Signatures/
  4. System Infected: Adware.NewAds Activity

System Infected: Adware.NewAds Activity

Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

Description

This signature detects Adware.NewAds communicating and requesting information from its controlling server.

Additional Information

When the program is executed, it creates the following files:

* %ProgramFiles%\Exolon\Exolon.dll
* %ProgramFiles%\Exolon\Exolon.exe
* %ProgramFiles%\Exolon\Uninstall.exe
* %ProgramFiles%\AdSponsor\AdSponsor.dll
* %ProgramFiles%\AdSponsor\Uninstall.exe
* %ProgramFiles%\PSupport\desktop.ini
* %ProgramFiles%\PSupport\pengine.sys
* %ProgramFiles%\PSupport\plibrary.dll
* %ProgramFiles%\PSupport\psupport.exe



Next, the program creates the following registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/html\"Default" = "Exolon.Decoder"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/html\"CLSID" = "{994D478A-45D0-4DB4-AE28-738B1E346F99}"

It also creates the following registry subkeys:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\AdBand.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{36946A0A-05A1-4CF7-934B-270571338E55}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2BC9C452-BB57-4896-A9A2-64611E06C5AA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6CA1C00B-90FC-4F3E-911F-95306ABA43AA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D5599FAE-28AA-4C2B-A29C-6C0CD5B245AA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AdBand.BandBHO
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AdBand.BandBHO.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AdBand.BandImpl
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AdBand.BandImpl.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{2BC9C452-BB57-4896-A9A2-64611E06C5AA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6CA1C00B-90FC-4F3E-911F-95306ABA43AA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AdSponsor
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6CA1C00B-90FC-4F3E-911F-95306ABA43AA}
HKEY_CURRENT_USER\Software\AdSponsor
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{994D478A-45D0-4DB4-AE28-738B1E346F99}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{1B8B502E-455B-4022-BE27-736D9F808A18}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04DCB17C-AB45-83AD-A86A-6DFB90277939}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{04DCB17C-AB45-83AD-A86A-6DFB90277939}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{04DCB17C-AB45-83AD-A86A-6DFB90277939}
HKEY_CURRENT_USER\Software\PadsysAssistant
HKEY_CURRENT_USER\Software\PSupport

The program installs itself as a Browser Helper Object.

It then displays pop-up advertisements.

The program may also download more adware on to the computer.

Affected

  • Windows 98
  • Windows 95
  • Windows XP
  • Windows Me
  • Windows NT
  • Windows Server 2003
  • Windows 2000

Response

The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.

1. Disable System Restore (Windows Me/XP).
2. Update the virus definitions.
3. Run a full system scan.
4. Delete any values added to the registry.
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube