|
|
Downloader DLLHLP Trojan Information
| Name: |
Downloader DLLHLP |
| Category: |
Trojan |
| Advice: |
Remove |
| Risk: |
High Risk
High risk threats typically are remotely exploitable vulnerabilities, which can lead to system compromise. Successful exploitation does not normally require any interaction. May open up communication ports, use polymorphic tactics, stealth installations, and/or anti-spy counter measures. May use a security flaw in the operating system to gain access to your computer. |
| Signatures:
|
at type: Trojan - A Trojan software is any software on a user's computer that the user is not aware or intentionally installed. Most Trojan software is designed to perform some sort of actions that could jeopardize the user's security or privacy.
Advice: Remove
Threat risk: High Risk
High risk threats typically are remotely exploitable vulnerabilities, which can lead to system compromise. Successful exploitation does not normally require any interaction. May open up communication ports, use polymorphic tactics, stealth installations, and/or anti-spy counter measures. May use a security flaw in the operating system to gain access to your computer.
Description: This trojan downloads and executes other programs from the internet. It also hijacks many Internet Explorer settings.
Downloader DLLHLP makes several copies of itself to Windows system directory using following file name: dllhlp.exe.
Downloader DLLHLP hijacks a number of Internet Explorer settings such as search and home pages. The following hajacks are made:
HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMain
"Search Bar" = http://youriskalka.com/sp.htm
HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMain
"Use Search Asst"= no
HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerSearchUrl
(Default) = http://youriskalka.com/index.htm
HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMain
"Search Bar" = http://youriskalka.com/sp.htm
HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMain
"Use Search Asst"= no
HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerSearchUrl
(Default) = http://youriskalka.com/index.htm
HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMain
"Use Search Asst"= no
HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerSearchUrl
(Default) = http://youriskalka.com/index.htm
It also adds itself as a startup entry to the Windows registry. The following registry key is created so that host32.exe is executed after each RESTART.
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersion
Run "dllhelp"= c:winntdllhlp.ex |
| Type: |
Trojan - A Trojan software is any software on a user's computer that the user is not aware or intentionally installed. Most Trojan software is designed to perform some sort of actions that could jeopardize the user's security or privacy. |
Top Trojan Visited Pages:
Tro.Downloader.loadadv - 411 visits
Enable Regedit - 195 visits
Java.ClassLoader.Dummy.d - 186 visits
Trojan.BankerSpy - 179 visits
RBot.steam - 86 visits
Startup.NameShifter.Xgtray - 77 visits
Tro.Bagle.SP - 59 visits
LRPatch Trojan - 58 visits
Trojan.BHO.NameShifter.EZ - 55 visits
Tro.YourStartingPage - 54 visits
Random Trojan Pages:
Trojan.Startup.NameShifter.GD
FakeGina.g
Gina Trojan - Alias: GinaPass.a
Trojan.Startup.NameShifter.HO
Spammer.Mail.Viv
Metallica.Batch
Trojan.BHO.NameShifter.DE
Virus.TLS.demo
Adult - Alias: adultchk, Trojan.Win32.Adu, W32/Adult.worm
Trojan.Startup.NameShifter.GL
|
|