Threat Profile: WNAD

Threat Search
Print
   
Virus Profile information details
Risk Assessment: Home N/A | Corporate N/A
Date Discovered: 10/8/2001
Date Added: 10/25/2001
Origin: Unknown
Length: Varies
Type: Program
Subtype: Adware
DAT Required: 4166
Removal Instructions
   
 
 
   

Description

This is a Potentially Unwanted Program (PUP) detection. It is not a virus or trojan. PUPs are any piece of software which a reasonably security-or privacy-minded computer user may want to be informed of.

Symptoms

N/A This is not a virus or trojan.

Method

N/A This is not a virus or trojan.

Aliases

WinAd
   

Virus Characteristics

This is an AdWare program which gets installed when the "Yo Mama, Osama!" game is installed. It is a memory resident application which periodically connects to a webserver to download and display pop-up window advertisements. It creates a registry run key to load itself at startup and does not uninstall itself:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\WNAD

Detection of this program was initially added to the 4166 DAT files as the WinAd Trojan. It was later discovered that the "Yo Mama, Osama!" installer required users to agree to the terms of the program which include the installation of this adware. As such, trojan detection of the program was removed in the 4167 DAT files. For those wishing to remove this program, manual removal instructions are provided below and the command line scanner will detect/remove this program as Application WNAD when including the /PROGRAM switch.

   
Manual removal

1) Press CTRL-ALT-DEL, select WNAD.EXE, and click END TASK
2) Click START | RUN, type %WINDIR% and hit ENTER
3) Delete the following files (if they exist):

WNAD.EXE
WNAD.DAT
WNAD-UPDATE.EXE

4) Click START | RUN, type REGEDIT and hit ENTER
5) Click on the plus sign next to HKEY_LOCAL_MACHINE
6) Click on the plus sign next to Software
7) Click on the plus sign next to Microsoft
8) Click on the plus sign next to Windows
9) Click on the plus sign next to CurrentVersion
10) Click on the Run folder
11) Click on WNAD on the RIGHT windows
12) Hit the DELETE key on the keyboard and hit ENTER
13) Close the REGISTRY EDITOR WINDOW