Virus

Adware/SideSearch

Analysis

Adware/Sidesearch is an Adware Installer for the Lycos Sidesearch.

The installer when executed will create a folder Sidesearch in C:\Program Files\Lycos.  It then extracts the following files:

offline.htm
sidesearch.dll
uninst.exe

Registry is updated with a new key Sidesearch into the following path:

HKEY_LOCAL_MACHINE\SOFTWARE\Lycos

Also, a Browser Helper Object is inserted to the registry:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00000762-3965-4A1A-98CE-3D4BF457D4C8}

After installing, the Adware sends an HTTP get to install.sidesearch.lycos.com. This pvoides a notification to that server that another machine has installed this adware.

Then, it creates a URL shortcut in Desktop. Also, it creates a Toolbar Button in Internet Explorer

Recommended Action

  • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option