Home Malware Programs Adware DNS Block

DNS Block

Posted: September 22, 2015

Threat Metric

Ranking: 8,385
Threat Level: 1/10
Infected PCs: 18,812
First Seen: July 20, 2015
Last Seen: March 4, 2025
OS(es) Affected: Windows

DNS Block is an annoying component that may find its way into your web browser application due to you installing random freeware programs from the internet. Once loaded, DNS Block is prone to causing pop-up messages or pop-up advertisements to appear that have sponsored content. Use of such DNS Block content may cause unwanted redirects on your web browser application to load up other sites that could have questionable content of offers of various services or products. Eliminating the actions of DNS Block may require use of an antimalware tool to find and remove all related components, including any web browser add-ons or extensions.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Windows\system32\DnsBlockUpdateSvc.exe File name: DnsBlockUpdateSvc.exe
Size: 76.83 KB (76832 bytes)
MD5: 00e0f83ab0e613c17c12b8246d3b6bdf
Detection count: 450
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\system32\DnsBlockUpdateSvc.exe
Group: Malware file
Last Updated: August 5, 2023

Registry Modifications

The following newly produced Registry Values are:

CLSID{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}{E7BF74EE-9106-4113-B216-2F980BA29141}{F2DB3739-77FB-41EB-9ED3-ABF34DF2DBF7}Regexp file mask%WINDIR%\System32\dns.block%WINDIR%\SysWOW64\dns.blockHKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\AppID\DPBHO.DLLSOFTWARE\Classes\DPBHO.DownloadProtectSOFTWARE\Classes\DPBHO.DownloadProtect.1SOFTWARE\Classes\WOW6432Node\AppID\DPBHO.DLLSOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{C654F3FE-8E84-4BB7-87CF-8D9171FC3C73}SYSTEM\ControlSet001\services\DnsBlockUpdateSvcSYSTEM\ControlSet002\services\DnsBlockUpdateSvcSYSTEM\CurrentControlSet\services\DnsBlockUpdateSvcHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{7b5da7f5-de7d-4e00-b330-a2e08e460095}

Additional Information

The following directories were created:
%LOCALAPPDATA%\DnsBlock%PROGRAMFILES%\DnsBlock%PROGRAMFILES(x86)%\DnsBlock
The following URL's were detected:
ads5_repl.js
Loading...