Threat Profile: Adware-BuddyLinks

Threat Search
Print
   
Virus Profile information details
Risk Assessment: Home N/A | Corporate N/A
Date Discovered: 2/10/2004
Date Added: 2/10/2004
Origin: Unknown
Length: Varies
Type: Program
Subtype: Adware
DAT Required: 4323
Removal Instructions
   
 
 
   

Description

This is a Potentially Unwanted Program (PUP) detection. It is not a virus or trojan. PUPs are any piece of software which a reasonably security-or privacy-minded computer user may want to be informed of.

Symptoms

N/A This is not a virus or trojan

Method

N/A This is not a virus or trojan
   

Virus Characteristics

This is not a virus or trojan. It is an potentially unwanted program that requires users to download an installer, agreeing to the terms of the program, which includes sending a messages to all users on your AOL Instant Messenger buddy list with a link to the installer page.

This application works when visiting the www.wgutv.com or download.buddylinks.net websites. A link to these sites arrives in an instant message.  Once this page has loaded, users are prompted to install and run a program.

The full license agreement is here:
http://www.wgutv.com/terms.html

Excerpt:

 ...In addition, the Software will interoperate with your current instant messaging client so as to permit the automatic sending of advertising messages originating from your Computer to your contact or "buddy" list regarding Content offered by PSD Tools or its suppliers. If you desire to stop this activity, you may elect to stop the messages by navigating to the "buddylinks.net" entry in your "Start Menu", selecting the "buddylinks.net Configuration" item, and unchecking the appropriate option. You may also refer to PSD Tools’ website at http://www.psdtools.com for an uninstaller

The application creates several directories in the following folders:

  • %Program Files%\buddylinks.net
  • %Program Files%\Common Files\PSD Tools

A registry run key is created to load one of the components:

  •  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
    Run "PSD Tools Channel" = C:\Program Files\Common Files\PSD Tools\ChannelUp.exe

The following files may be present on a machine that has run this application:

  • %Start Menu%\buddylinks.net\Games\Saddam Escapes\Play.lnk
  • %Start Menu%\buddylinks.net\Games\Saddam Escapes\Uninstall.lnk
  • %Program Files%\buddylinks.net\Games\Saddam Game\Disabled.jpg
  • %Program Files%\buddylinks.net\Games\Saddam Game\Down.jpg
  • %Program Files%\buddylinks.net\Games\Saddam Game\Mask.bmp
  • %Program Files%\buddylinks.net\Games\Saddam Game\Normal.jpg
  • %Program Files%\buddylinks.net\Games\Saddam Game\Over.jpg
  • %Program Files%\buddylinks.net\Games\Saddam Game\saddam.swf
  • %Program Files%\buddylinks.net\Games\Saddam Game\shell.exe
  • %Program Files%\buddylinks.net\Games\Saddam Game\skin.ini
  • %Program Files%\buddylinks.net\Games\Saddam Game\uninst.exe
  • %Program Files%\Common Files\PSD Tools\ChannelUp.exe
  • %WinDir%\Downloaded Program Files\ShellInstaller.INF
  • %WinDir%\Downloaded Program Files\ShellInstaller.ocx
  • %temp%\game_dl.exe
  • %temp%\game_install.exe

The following registry keys are also evidence that this application was run:

  • HKEY_CLASSES_ROOT\Interface\{00D38C81-14B3-44DE-B023-3BDC5BDE4FEC
  • HKEY_CLASSES_ROOT\CLSID\{FDDCE9FF-1FC6-413C-80B1-37B101FDA1D4}
   

To uninstall this application, use the ADD/REMOVE Programs Control Panel and remove the applications related to:

  • BuddyLinks
  • PSDT Messaging Integration
  • PSD Tools ChannelUp v1.0 (remove only)

For VirusScan 4.x users who would like to detect this program on their system, they can run the command line scanner with the /PROGRAM switch.

  1. Click the START button
  2. Click RUN
  3. Type COMMAND and hit ENTER
  4. Type:

    c:\progra~1\common~1\networ~1\viruss~1\4.0.xx\scan.exe c: /program /sub

    and hit ENTER.

Users running VirusScan 7 or later can also enable application or joke detection via the configuration option "Find potentially unwanted programs" (Advanced section - see example below), within the VirusScan GUI as shown below:

Corporate Users:

This applies for the VirusScan 7 Enterprise On-Access scanner too.

Retail Users:

This does not apply for the VirusScan 7 Retail On-Access scanner.