Threat Description

Adware:​W32/Stud

Details

Category: Spyware
Type: Adware
Platform: W32

Summary



This program delivers advertising content to the user. It is usually annoying but harmless, unless it is combined with spyware or trackware.



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

You may wish to refer to the Support Community for further assistance. You also may also refer to General Removal Instructions for a general guide on alternative disinfection actions.



Technical Details



This is the family description for the Adware:W32/Stud family of adware.

Like most adware programs, it displays pop-up advertisements. Members of the Stud adware family also gather data on the web searches made by the user.

Installation

During installation, the user is prompted to read and agree to an end user license agreement (EULA) before proceeding with the installation:

Should the user agree and click on "Next", the adware installs a DLL into the %system32% folder, then registers it as a Browser Helper Object (BHO). This means that each time the Microsoft Internet Explorer browser is started, the adware program is also automatically launched.

Activity

In addition to displaying pop-up advertisements, Stud adware programs are able to auto-update. To do so, the program must connect with a remote system to download the necessary components/updates. An example of a possible connection is:

  • http://xfind.to/[...]/version.htm?[...]





SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More