Home / malwarePDF  

Adware:Win32/Digfast.A


First posted on 11 June 2009.
Source: SecurityHome

Aliases :

Adware:Win32/Digfast.A is also known as Also Known As:Win-Trojan/Agent.716800.P (AhnLab), Trojan-Downloader.Win32.Agent.bozu (Kaspersky), Mal/Inet-Fam (Sophos).

Explanation :

Adware:Win32/Digfast.A is a program that displays advertisements. It connects to a remote server to retrieve configuration data and the advertising content that it displays.

Symptoms
There are no obvious symptoms that indicate the presence of this program on an affected machine.

Adware:Win32/Digfast.A is a program that displays advertisements. It connects to a remote server to retrieve configuration data and the advertising content that it displays.

Installation
Adware:Win32/Digfast.A may be installed by an ActiveX control when a user visits www.digi-fast.com.Additional informationAdware:Win32/Digfast.A connects to "www.digi-fast.com" to report its installation and supplies information to the remote host that includes the affected user's operating system and IE version. It then downloads a configuration file to <malware folder>config.cfg.
Adware:Win32/Digfast.A connects to "www.digi-fast.com" to retrieve commands that determine how the advertising content will be displayed (e.g. how often, in what format, etc), and from where it will be served. In the wild, this program was observed serving advertisements from sitetrackingmeter.com.

Analysis by Shawn Wang

Last update 11 June 2009

 

TOP