Home Malware Programs Spyware Heoms

Heoms

Posted: March 28, 2006

Heoms is a malware trojan that tracks user Internet activity and records addresses of visited web sites. Gathered information is transferred to a predetermined remote server. Heoms is able to silently update itself via the Internet. The spyware automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 dvdsdtl.dll
    2 heomstool.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOTdvdsdtl.IEBrowserHelperHKEY_CLASSES_ROOTvddsdlsHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunheomstool
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}E694E3DC-723F-40C7-87FE-6FFC222AD122
Loading...