|
Hijacker.Explorer32 Browser Hijacker Information
| Name: |
Hijacker.Explorer32 |
| Category: |
Browser Hijacker |
| Advice: |
Remove |
| Risk: |
Elevated Risk
Elevated threats are usually threats that fall into the range of adware in which data about a user's habits are tracked and sent back to a server for analysis without your consent or knowledge. |
| Description:
|
Hijacker.Explorer32 is a Trojan which modifies the Internet Explorer Start-Page and changes the Search options.
When run the Trojan creates two helper files system32.exe and mspxs32.dll in the Windows system folder and runs system32.exe. The following registry entries are created so that the Trojan may auto-start on user logon or computer restart:
HKLMSoftwareMicrosoftWindowsCurrentVersionRun Win32 Explorer = %SYSTEM%explorer32.exe
HKCUSoftwareMicrosoftWindowsCurrentVersionRun Win32 Explorer = %SYSTEM%explorer32.exe
Hijacker.Explorer32 also lowers the Internet.
Other variants:
Microsoft Windows Updates: Added by the SDBOT.VQ WORM!
Win32 Explorer: StartPa-MN homepage hijacker
Windows Explorer Update Build 1142: Added by the KaZaA based KWBOT or KWBOT.Y WORMS!
|
| Signatures:
|
process: explorer32.exe: MD5 Hash: 61655292959d14caf99...
process: explorer32.exe: MD5 Hash: a5651c45ce14208c1f0...
process: explorer32.exe: MD5 Hash: d641a0db991d4af9697...
process: explorer32.exe: MD5 Hash: 0b255955afcaa388b3c...
process: explorer32.exe: MD5 Hash: 252644ebd49a48cae8d...
process: explorer32.exe: MD5 Hash: d0a38b1020c2b80fe0c...
process: explorer32.exe: MD5 Hash: ...
process: explorer32.exe: MD5 Hash: d813491fadde113834e...
process: explorer32.exe: MD5 Hash: 80f0b62f19f33b8286b...
process: explorer32.exe: MD5 Hash: 671f2019d4320ea3f69.. |
| Type: |
Browser Hijacker - A Trojan software is any software on a user's computer that the user is not aware or intentionally installed. Most Trojan software is designed to perform some sort of actions that could jeopardize the user's security or privacy. |
Top Browser Hijacker Visited Pages:
SuperSpider - Alias: Network Security Guard, Melcosoft - 324 visits
Spyass.com - 67 visits
Tubby - Alias: MakeMeSearch, CoolWebSearch.Tubby, Spyware.Arau, Trojan.Win32.StartPage.ih, Trojan.StartPage-FJ - 55 visits
CrackSpider - Alias: Troj/Favadd-D - 51 visits
CoolWebSearch - Alias: CWS, Cool Web Serach, CoolWwwSearch - 50 visits
SecurityToolbar.DesktopScam - 46 visits
Paytime - 41 visits
Trojan.StartPage - Alias: SearchCentral - 37 visits
Search3 Hijacker - 31 visits
SBSoft - 31 visits
Random Browser Hijacker Pages:
ActualNames - Alias: AdvSearch, SearchPike, BrowseProxy
CnsMin - Alias: 3721.com
Secret Crush
IESearchToolbar
GIGA Search - Alias: Search Bar
iLookup.GlobalWebSearch - Alias: global Search Page, Worldanywhere Toolbar, Hotwebsearch Toolbar,Bigwebportal Toolbar, Searchitquick
SBSoft
BHO.System61
MyPageFinder
Searchex
|