Name: IEPlugin
Category: Spyware
Advice: Remove
Risk: Elevated Risk Elevated threats are usually threats that fall into the range of adware in which data about a user's habits are tracked and sent back to a server for analysis without your consent or knowledge.
Description: IEPlugin is an IE Browser Helper Object that monitors site addresses, content entered into forms, and even local filenames browsed, and pops up advertisements when it sees a targeted keyword.

In addition to IEPlugin being spyware itself, installation includes other spyware including 180Search Assistant, Bargian Buddy, Clip Genie, TV, and Middleaddle.

IEPlugin displays an advertisement when it sees a targeted keyword. It will also install a running process to update itself by contacting servers every few minutes. This adware may also add a few bookmarks to your Favorites menu.

IEPlugin attempts to connect to an IP address that the IEPlugin predefines. IEPlugin may post the victim's information to a script file on that particular Web server.

IEPlugin is written and distributed by InfoAge Marketing International, who also run the 123Webhost and JupiterTech hosting services. However, it seems as well as spyware, IMI are also involved in writing spam-sending software ("Godmail") and a marketing operation for pheromone pills ("Flatcash").

From the EULA: "UPDATES. You grant IEPL permission to add/remove features and/or functions to the Software and/or Service, or to install new applications, at any time, in IEPLís sole discretion with or without your knowledge and/or interaction. You also grant IEPL permission to make any changes to the Software and/or Service provided at any time.

7. SERVER INTERACTION. You understand and accept that when the Software is installed, it periodically communicates with server(s) operated by IEPL and/or third party servers.

8. COLLECTION AND USE OF YOUR PERSONAL INFORMATION AND YOUR PRIVACY CONSENT. You understand and grant IEPL permission to assign a unique software identify code to your copy of the Software. You also grant IEPL permission to collect and store information of your internet usage habit, including but not limited to information about every web page you view with the full Uniform Resource Locators, and the content of web page. You understand and accept that Uniform Resource Locators and the content of web pages you view may include your personally identifiable information. You grant IEPL permission to collect and store information on which toolbar buttons you click on, your response to advertising, the search terms you entered on the toolbar and/or all other information relates to your internet usage habit. IEPL may at times ask you for your personally identifiable information, such as name, address, email address, postal/zip code, and telephone number. You hereby grant IEPL permission to store such information in a separate database. You hereby grant IEPL permission to distribute your non personally identifiable information, to the extent permitted by law, to our partners, agents, and/or any third party in IEPL's sole discretion. IEPL does not currently enable users to access, review, edit, or delete information, including internet usage information, collected during use of the Service. By using the IEPL Software and/or Service you agree, to the extent permitted by law, to waive any constitutional, common law, statutory, or regulatory right of access to such information that you might otherwise have or acquire. If you have any further queries relating to our Privacy Policy, or you have a problem or complaint, please contact us at

8.1. THIRD PARTY ADVERTISING AND COOKIES. We work with MaxWorldWide and other third party advertising companies to serve advertisements when you visit our web sites and use the Service. These companies may use information (not including your name, address, email address or te

Signatures: process: ie_plugin.exe: MD5 Hash: f0474d530aecf4c4219... process: wupdt.exe: MD5 Hash: c46e7b76adfd38e7a6a... process: wupdt.exe: MD5 Hash: a6be72104be5eb9b5b1... process: wupdt.exe: MD5 Hash: ... process: winserv.exe: MD5 Hash: ... process: extract.exe: MD5 Hash: ... process: extract.exe: MD5 Hash: ... process: se.exe: MD5 Hash: 6788b1991ade9b017c3... process: wupdt.exe: MD5 Hash: bc6c7ef520da46ecddf... process: wdskctl.exe: MD5 Hash: d074582eac0c9c7e1ad... process: rgrt.exe: MD5 Hash: e008561845bfc7a227f... process: systb.exe: MD5 Hash: ... process: wupdt.exe: MD5 Hash: ... process: wupdt.exe: MD5 Hash: e583e4bf55ed1d919a4... process: wupdt.exe: MD5 Hash: dce46bb098a48e482d4... process: wupdt.exe: MD5 Hash: 9a915f93c86f19585ac... process: systb.exe: MD5 Hash: ... process: wupdt.exe: MD5 Hash: 88593a98662470e9916... process: systb.exe: MD5 Hash: 9ff0ac1eb4e9b379ac5... process: wupdt.exe: MD5 Hash: 6fa71b2555c0d85c0f3... process: wupdt.exe: MD5 Hash: 142478b0fd44f74ef9e... process: tdtb.exe: MD5 Hash: 9ff0ac1eb4e9b379ac5... process: invitessk.exe: MD5 Hash: eb311b1b40e5b5f7366... process: offerssk.exe: MD5 Hash: 140f76d3c4ab0fcc1ab... process: rifvlxmcj.exe: MD5 Hash: c1802f55ece3c45594d... process: ssk.exe: MD5 Hash: fd3493168599727e5ef... process: eltupt.exe: MD5 Hash: eabe4008a1d66a45349... process: f206812.exe: MD5 Hash: 60f5343fef0ebbb0b04... process: f213187.exe: MD5 Hash: 2c10db62a34b74bfd32... process: grabburn.exe: MD5 Hash: ae9143a39637f52932b... process: wupdt.exe: MD5 Hash: bc6c7ef520da46ecddf... process: wupdt.exe: MD5 Hash: bc6c7ef520da46ecddf..
Type: Spyware - Spyware's primary purpose is to collect demographic and usage information from your computer, usually for advertising purposes. Spyware usually that 'sneaks' onto a system or performs other activities hidden to the user. Spyware programs are usually bundled as a hidden component and downloaded from the Internet. These modules are almost always installed on the system secretively and try to run secretively as well.

