Home Malware Programs Adware HDTBar

HDTBar

Posted: March 28, 2006

HDTBar is an adware spyware that installs an Internet Explorer toolbar and shows undesirable commercial advertisements. It also may download arbitrary files from the Internet. HDTBar can silently get into the computer while visiting some insecure web sites.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 barhelper22.0.dll
    2 iebar22.0.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOTDownloadBHO.T2BHOHKEY_CLASSES_ROOTDownloadBHO.T2BHO.1HKEY_CLASSES_ROOTHDT_BAR.HDT_BARObjHKEY_CLASSES_ROOTHDT_BAR.HDT_BARObj.1HKEY_CURRENT_USERsoftwareHDTHDTBarHKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionUninstallHDTBar
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}E35306D7-B44C-4530-A2CE-94C60F8CC4DC1F77F67E-BD08-4932-AF5A-15FD532EEDB19AAABFE1-22A9-4E0D-8F4A-48B9696A199B691CC615-CD3F-41FF-920D-60769D3DCF5BB1D147E7-873E-4909-8127-695D9BB7872856A7DC70-E102-4408-A34A-AE06FEF01586
Loading...