|
· Overview ·
|
Overview |
|
Summary: |
Adware.DownloadPlus is an adware program that connects to a predetermined site and displays pop-ups advertisements. |
Vendor Notes: |
DownloadPlus is a process run at Windows startup which opens pop-up adverts (many of them porn-related) and, for some reason, weather reports. |
Alias: |
Adware.DownloadPlus, TrojanDownloader.Win32.Lalus |
Category: |
Adware: Software that displays popup/popunder ads when the primary user interface is not visible or which do not appear to be assocaited with the product. Downloader: A program designed to retrieve and install additional files, when run. Most will be configured to retrieve from a designated web or FTP site. |
Variants: |
|
Similar Pests: |
Adware · Downloader |
Origins |
|
Group: |
Porn Kings |
By This Group: |
|
Date of Origin: |
Variants from May, 2003 to May, 2003 |
Distribution |
|
Distribution: |
Installed by ActiveX drive-by download in pop-up ads (via DownloadPlus/MCInst). Also loaded by the ISTbar/AUpdate parasite. In this case there is no ActiveX installer control, and the script at this site will be unable to detect DownloadPlus. |
Prevalence: |
|
Clot Factor: |
The "Clot Factor" is a measure of how much a pest "gums up" a machine by adding registry entries, files, and directories. As more objects are placed in a machine, manual removal becomes more difficult and more error-prone. |
Growth: |
|
Operation |
|
Platform: |
Windows 2000, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP |
Advertising: |
Yes. Downloads an untargeted list of adverts to show from its controlling server tnc4u.com, and opens them periodically as pop-unders. |
Storage Required: |
|
Risks |
|
Security Issues: |
Yes. Can silently download and execute arbitrary unsigned code from its controlling server, as a self-updating feature. |
Detection and Removal |
|
Automatic Removal: |
|
Manual Removal: |
Browse to the startup folder. This is done by clicking Start -> (All) Programs -> Startup. Right-click 'Download Plus' and choose delete. Restart your computer. Start Windows Explorer and delete: %AppData%\DownloadPlus.exe Note: %AppData% is a variable (?). By default, this is 'C:\WINDOWS\Profiles\%UserName%\Application Data\' or 'C:\WINDOWS\Application Data\' (Windows 95/98/Me) or 'C:\Documents and Settings\%UserName%\Application Data\' (Windows NT/2000/XP). Note: %UserName% is a variable (?). This is set to your username. |
| Stop Running Processes: Kill these running processes with Task Manager: | |
| Unregister DLLs: Unregister these DLLs with Regsvr32, then reboot: | |
| Clean Registry: Remove these registry items (if present) with RegEdit: | |
| Remove Files: Remove these files (if present) with Windows Explorer: | |
Research |
|
File Analyses: |
|
More Info: |
|
Research By: |
|
Last Revised: |
April 02, 2005 |