NicTech Networks Description of Adware: NicTech is a company well known for Adware products. The above installers that have been labeled "Sample 1" and "Sample 2" for simplicity are just two of many known installers authored by NicTech.
The two referenced do vary considerably in their payload however. Upon executing the installer for Sample 1, no EULA, or notification occurs, and two Internet shortcuts on the user's desktop that resolve to pornographic websites.
Sample 2 is however far less benign. The difficulty is, the installer is already downloading, and installing files during the display of the EULA. Upon installing Sample 2, many system changes take place.
These changes have the purpose of displaying advertisements, stealthily installing software, and preventing removal of the unlaying adware. Particularly troubling is the program's lack of an uninstaller; the system changes made by Sample 2 appear to be irreversible.
One can view the details of the system alterations and behavior of this Adware by examining the sections below. System alterations upon installation: Sample 1 Executing an installer of 87, bytes, and signed by NicTech Networks brought no user-visible output.
The following files were dropped: A registry entry was added: However, during the display of the EULA the program is already installing.
Should one run packet analysis software, several activities can be seen occuring while the EULA is displayed. A DNS query to sites such as www. Notification of installation to NicTech's network. Execution of a client-side script from the NicTech network. Download of an archived installation file from the NicTech network. These modifications actually disable advertisements from other companies by re-directing DNS queries for them to the localhost IP address of However many system changes take place.
Including the downloading of several archived installer files from the NicTech network. The installer may attempt to reboot the system without user confirmation.
Several files are added to the system including: