Home Malware Programs Adware IEDriver

IEDriver

Posted: March 28, 2006

IEDriver is an adware spyware that serves large amount of commercial pop-up advertisements and modifies Internet Explorer default web search settings. The threat also downloads from the Internet and executes arbitrary potentially harmful files. These files can be IEDriver updates or dangerous third-party spywares. The spyware is bundled with some advertising-supported products. It can also get into the computer while visiting some insecure web sites. IEDriver runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 [X].exe
    2 iedriver.exe
    3 ieupdate.exe
    4 sb.htm
    5 td.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainSearchBar=[filename]HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunIEDriverHKEY_LOCAL_MACHINESOFTWARETurboDownloadConnectionType=0x1
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}F20239CB-33DC-4ec6-959E-73EDEA0FE4D714D108C8-DD97-4b78-8B50-C981500ABB8F1A00C40B-DA85-4aa3-A67F-582D9347EECDBC3BBF86-E4EC-4412-9676-8355468B3B05
Loading...