Need help? Ask the community or hire an expert.
Go to Avira Answers
Virus:Adware/Agent.NFM
Date discovered:28/06/2011
Type:Adware
In the wild:No
Reported Infections:Low
Distribution Potential:Low
Damage Potential:Low
Static file:Yes
File size:20.480 Bytes
MD5 checksum:a6a8ad9a95b8ea0cfe00c6f8ea78332f
VDF version:7.11.10.133 - Tuesday, June 28, 2011
IVDF version:7.11.10.133 - Tuesday, June 28, 2011

 General ADWARE/ malware class description (en)
Method of propagation:
   • No own spreading routine


Aliases:
   •  Kaspersky: AdWare.Win32.Agent.vco
   •  Bitdefender: Adware.Agent.NFM


Platforms / OS:
   • Windows 95
   • Windows 98
   • Windows 98 SE
   • Windows NT
   • Windows ME
   • Windows 2000
   • Windows XP
   • Windows 2003
    Windows Vista
    Windows Server 2008
    Windows 7


Side effects:
    Opens website in web browser

 Miscellaneous Accesses internet resources:
   • ads.eorezo.com; action.metaffiliation.com; www.spartoo.com;
      static7.spartoo.com; s7.addthis.com; img6.spartoo.com;
      photos5.spartoo.com; photos4.spartoo.com; ads.bluelithium.com;
      img7.spartoo.com; www.google-analytics.com; webnibal.spartoo.com;
      cf.addthis.com; l.addthiscdn.com; segment-pixel.invitemedia.com;
      rainbow.mythings.com; cm.g.doubleclick.net; g-pixel.invitemedia.com;
      vu.veoxa.com; ad.yieldmanager.com; www.googleadservices.com;
      googleads.g.doubleclick.net; ld2.criteo.com;
      spartoo.widget.criteo.com; widget.fr.eu.criteo.com;
      dis.jp.as.criteo.com


String:
Furthermore it contains the following string:
   • ad string [http://ads.]

 File details Programming language:
The malware program was written in MS Visual C++.


Runtime packer:
In order to aggravate detection and reduce size of the file it is packed with a runtime packer.

Description inserted by Jason Soo on Wednesday, June 29, 2011
Description updated by Jason Soo on Wednesday, June 29, 2011

Back . . . .