Threat Description

Adware:​W32/Stud

Details

Category: Spyware
Type: Adware
Platform: W32

Summary


This program delivers advertising content to the user. It is usually annoying but harmless, unless it is combined with spyware or trackware.



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

Detailed instructions for F-Secure security products are available in the documentation found in the Downloads section of our Home - Global site.

You may also refer to the Knowledge Base on the F-Secure Community site for further assistance.



Technical Details


This is the family description for the Adware:W32/Stud family of adware.

Like most adware programs, it displays pop-up advertisements. Members of the Stud adware family also gather data on the web searches made by the user.

Installation

During installation, the user is prompted to read and agree to an end user license agreement (EULA) before proceeding with the installation:

Should the user agree and click on "Next", the adware installs a DLL into the %system32% folder, then registers it as a Browser Helper Object (BHO). This means that each time the Microsoft Internet Explorer browser is started, the adware program is also automatically launched.

Activity

In addition to displaying pop-up advertisements, Stud adware programs are able to auto-update. To do so, the program must connect with a remote system to download the necessary components/updates. An example of a possible connection is:

  • https://xfind.to/[...]/version.htm[...]


SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Scan & clean your PC

F-Secure Online Scanner will scan and clean your PC in just a few minutes for free

Learn More