Home Malware Programs Adware IEhlpr

IEhlpr

Posted: March 28, 2006

IEhlpr is an adware application, which shows commercial advertisements written mostly in Chinese. The threat regularly contacts a predetermined web server and downloads updated configuration settings. IEhlpr must be manually installed. It works as the web browser's add-on and runs every time the user launches Internet Explorer.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 hmapi.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOTIEHlprObj.IEHlprObjHKEY_CLASSES_ROOTIEHlprObj.IEHlprObj.1
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}EE7C3CE2-4B15-11D1-ABED-709549C10000EE7C3CEF-4B15-11D1-ABED-709549C10000EE7C3CF0-4B15-11D1-ABED-709549C10000

Related Posts

Loading...