SPYWARE: Downloader ARL 2
This signature detects the runtime behavior of Downloader ARL spyware. Download ARL downloads malicious code based on the server response. It posts user information to its controlling server without user consent and also changes the Internet Explorer (IE) auto search engine.
References
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3