Home Malware Programs Adware DealHelper.com

DealHelper.com

Posted: March 28, 2006

DealHelper is an adware program designed to show annoying advertisements in web browser windows, pop-ups or undesirable toolbars. DealHelper can be distributed with ad-supported software, some malicious sites may install to the computer without user permission. DealHelper.com receives commercial data and updates from its home servers. On occasion it can perform additional malicious actions, such as browser hijacking or tracking user activity in the Internet. The threat is able to start automatically on every Windows startup and remain hidden in background. Its activity violates user privacy and affects computer performance.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 7.13.2004.11.32.58....0.reg
    2 [system32]dealhlpr.dll
    3 [system32]dp-him.exe
    4 [system32]dp-k13w13.exe
    5 [system]dealhlpr.dll
    6 _setupx.dll
    7 appsinstalled.htm
    8 dealhelper.com
    9 dealhlpr.dll
    10 dhbrwsr.exe
    11 dhdom.bin
    12 dhdomp.bin
    13 dhkw.bin
    14 dhp.dll
    15 dhp2.dll
    16 dhsigned.ocx
    17 dhsvr.exe
    18 dhun.exe
    19 dhupdt.exe
    20 dsearch.bin
    21 edow.exe
    22 imesynchronize.exe
    23 imesyncsetup.exe
    24 imesyncsetup.ini
    25 incdealhelpersetup.exe
    26 uninstall.exe
    27 uninstall.exeupdater.exeupdater.exe-0be15c50.pf
    28 updater.exe
    29 virtue350757dealhelper.exe

Registry Modifications

  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}e9468a08-f790-48ce-ad30-eadeeab9b40c
Loading...