Threat Description

Adware:​W32/Stud

Details

Category: Spyware
Type: Adware
Platform: W32

Summary



This program delivers advertising content to the user. It is usually annoying but harmless, unless it is combined with spyware or trackware.



Removal



Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.



Technical Details



This is the family description for the Adware:W32/Stud family of adware.

Like most adware programs, it displays pop-up advertisements. Members of the Stud adware family also gather data on the web searches made by the user.

Installation

During installation, the user is prompted to read and agree to an end user license agreement (EULA) before proceeding with the installation:

Should the user agree and click on "Next", the adware installs a DLL into the %system32% folder, then registers it as a Browser Helper Object (BHO). This means that each time the Microsoft Internet Explorer browser is started, the adware program is also automatically launched.

Activity

In addition to displaying pop-up advertisements, Stud adware programs are able to auto-update. To do so, the program must connect with a remote system to download the necessary components/updates. An example of a possible connection is:

  • http://xfind.to/[...]/version.htm?[...]





SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More