Home Malware Programs Spyware IESearch

IESearch

Posted: March 28, 2006

IESearch is a malware application that adds a search toolbar to Internet Explorer. However, it also monitors all network and Internet traffic to and from the compromised PC and hijacks the web browser by changing its default home, search and error pages and modifying some related settings. IESearch works as an Internet Explorer add-on and therefore runs every time the user launches the web browser. Some of its components run on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 config.xml
    2 iebho.dll
    3 ielsp.dll
    4 versionchecker.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOTAppIDIEBHO.DLLHKEY_CLASSES_ROOTIEBHOProject.IEBHOHKEY_CLASSES_ROOTIEBHOProject.IEBHO.1HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainAutoSearch=5HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerMainStartPage=[siteaddress]HKEY_LOCAL_MACHINESOFTWAREIEsearchHKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerMainSearchBar=[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternetExplorerSearchSearchAssistant=[siteaddress]HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallIESearch
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}E128D984-2F06-41D0-B55C-0EAAE5913436901C2C91-AFE7-416D-9FC1-34F87A264AC82E97A338-5092-4B14-B5E7-50994E09EA35

Related Posts

Loading...