Internet Optimizer, also known as DyFuCA is an
adware
Adware, often called advertising-supported software by its developers, is software that generates revenue for its developer by automatically generating online advertisements in the user interface of the software or on a screen presented to the ...
and a
spyware
Spyware (a portmanteau for spying software) is software with malicious behaviour that aims to gather information about a person or organization and send it to another entity in a way that harms the user—for example, by violating their privac ...
program, which first appeared in 2003.
It typically redirects
Internet Explorer
Internet Explorer (formerly Microsoft Internet Explorer and Windows Internet Explorer, commonly abbreviated IE or MSIE) is a series of graphical user interface, graphical web browsers developed by Microsoft which was used in the Microsoft Wind ...
error pages to advertising pages. It may be installed as a drive-by download via an
ActiveX
ActiveX is a deprecated software framework created by Microsoft that adapts its earlier Component Object Model (COM) and Object Linking and Embedding (OLE) technologies for content downloaded from a network, particularly from the World Wide Web. ...
component, usually via nuisance affiliate porn webpage popups. Users suspicions are lulled by its installer title as ''Internet Optimizer'' under the guise of the name of the otherwise unrelated
Moneytree
Moneytree, Inc. is a retail financial services provider headquartered in Tukwila, Washington, with branches in Washington, California, Colorado, Idaho, Nevada, and British Columbia. Moneytree offers payday loans, installment loans, prepaid d ...
, while the
C&C domains accessed were usually named with the prefix "''mtree''".
When users follow a broken link or enter an erroneous URL, instead of the browser's internal
default error status page, they see an internet page of advertisements. Password-protected Web sites or pages will prompt for a missing or required user name and password via a pop-up request, this HTTP Basic authentication uses the same mechanism as HTTP errors, thus Internet Optimizer inadvertently interferes and makes it impossible for the user to access password-protected sites or pages.
It uses the "
Browser Helper Object
A Browser Helper Object (BHO) is a DLL module designed as a plugin for the Microsoft Internet Explorer web browser to provide added functionality. BHOs were introduced in October 1997 with the release of version 4 of Internet Explorer. Most B ...
" or BHO interface, and as such, it loads whenever MS Internet Explorer starts and may be ignored by firewalls or not flagged by anti-virus software, as it is seen as a legitimate part of the browser application.
It is also classified as a "downloader" which can download, install and run
malevolent
Malevolence may refer to:
* Evil
* Hostility
* Malice (law)
* Sadistic personality disorder, Sadism, the experience of feeling pleasure from the pain of others.
Other uses
* Malevolence (band), an English hardcore punk band from Sheffield
* ...
software on the victim's computer without their knowledge or permission.
References
External links
*
Spyware
{{Malware-stub