威胁数据库 广告软件 广告软件.Linkular

广告软件.Linkular

Adware.Linkular被归类为广告软件,这是一种旨在通过向用户投放广告来为其开发者牟利的恶意软件。此类程序通常与其他下载程序捆绑在一起,并且往往在安装和运行过程中不向用户提供清晰、知情的控制权。虽然 Adware.Linkular 的具体技术细节尚未得到独立证实,但其行为与广告软件家族的其他成员一致,这意味着它应被视为恶意软件,会对浏览体验和系统整体性能产生负面影响。

Adware.Linkular 的作用

与大多数广告软件一样,Adware.Linkular 旨在向受感染的计算机注入或显示广告内容。这些内容可能包括弹出式广告、横幅广告、文本链接、插页式广告或重定向到赞助网站。此类广告软件通常会修改浏览器设置、向网页注入脚本或运行后台进程,持续投放广告,而不管用户实际访问的是哪个网站。在许多情况下,这样做是为了给分发广告软件的人赚取点击付费或展示付费收入,而这往往会损害用户的浏览体验并占用系统资源。

它通常是如何进入电脑的

像 Adware.Linkular 这样的广告软件通常通过软件捆绑传播,它们会与免费程序、浏览器扩展程序或第三方网站的下载内容打包在一起。用户经常会在不知不觉中安装这类广告软件,例如匆忙完成安装向导并接受默认设置而未仔细查看可选的附加组件。此外,它也可能通过欺骗性广告、虚假的软件更新提示或不可靠网站上的误导性下载按钮传播。

用户面临的风险

虽然广告软件通常被认为不如更具破坏性的恶意软件严重,但它仍然会带来切实的风险。广告软件感染的常见后果包括:

  • 侵入性强且过多的广告会干扰正常的浏览体验。
  • 后台进程导致系统和浏览器性能变慢。
  • 通过广告重定向可能接触到恶意或诈骗网站
  • 浏览器设置(例如主页或默认搜索引擎)发生不必要的更改
  • 收集浏览数据或习惯,并可能与第三方共享以用于定向广告。

感染迹象

使用 Adware.Linkular 等广告软件的用户可能会注意到以下几个警告信号:

  • 弹出式广告或横幅广告突然增多
  • 在通常不显示广告的网站上出现的广告
  • 浏览器意外重定向到陌生或可疑页面
  • 非故意安装的新工具栏、扩展程序或搜索引擎
  • 浏览器或系统性能明显变慢

如何做好防护

为了降低感染广告软件的风险,用户应仅从官方或可信来源下载软件,避免使用捆绑额外程序的第三方下载网站。安装过程中,务必选择自定义或高级安装选项,以便查看并拒绝任何额外提供的软件、工具栏或扩展程序。此外,保持浏览器和操作系统更新、定期检查已安装的程序和浏览器扩展程序,并对意外弹出的窗口或更新提示保持警惕,也有助于从源头上预防 Adware.Linkular 等广告软件的安装。

分析报告

一般信息

姓: Adware.Linkular
签名状态: No Signature

已知样本

MD5: 4025b6c9e6d156a0658440799f523e50
SHA1: b09762cee50feb6827f9f4ac118d00c4b75b5905
SHA256: AEE1EBD250C97ED895F1D2BA158911018E870EE86A066CD763E853EA2F0F6B90
文件大小: 467.69 KB,467695字节

Windows 可移植可执行文件属性

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
显示更多
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

文件图标

Windows PE 版本信息

姓名 价值
Company Name Company
File Version 2.2.2.1634.1634
Legal Copyright Linkular LLC, 2012
Product Name App Name
Product Version 2.2.2.1634.1634

文件特征

  • Installer Manifest
  • Installer Version
  • nosig nsis
  • Nullsoft Installer
  • x86

文件已修改

文件 属性
\device\namedpipe Generic Read,Write Attributes
\device\namedpipe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsf2ac1.tmp\inetc.dll.out0 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsf2ac1.tmp\inetc.dll.out1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsf2ac1.tmp\mf.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsf2ac1.tmp\nsexec.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsf2ac1.tmp\system.dll Generic Write,Read Attributes

注册表修改

键::值 数据 API名称
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 骹儯ǝ RegNtPreCreateKey

Windows API 使用情况

类别 API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
显示更多
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Shell命令执行

C:\Users\Dlscroad\AppData\Local\Temp\nsf2AC1.tmp\mf.exe "C:\Users\Dlscroad\AppData\Local\Temp\nsf2AC1.tmp\inetc.dll"