Content

Spyware-DCToolbar

Type
Program
SubType
Spyware
Discovery Date
10/28/2003
Minimum DAT
4302 (11/05/2003)
Updated DAT
4427 (02/09/2005)
Minimum Engine
5.1.00
Description Added
10/28/2003
Description Modified
10/31/2003 8:08 AM (PT)

Tab Navigation

Characteristics

The entry for the Spyware-DCToolbar application/program was added to cover for a file called "redirect2.exe " , having a filesize of 32768 bytes decimal. The file is a 32 bit PE file, written with MSVB60 and is not compressed internally.

When the file redirect2.exe is being run, it runs silently, no GUI messageboxes appear. However, its process is visible in the Windows Task Manager.

It also makes a standard registry entry to call itself at startup: HKLM\Software\Microsoft\Windows\CurrentVersion\Run

  • name:  redirect
  • data:   location of redirect2.exe (It didn't copy itself to another directory)

Note that the file redirect2.exe (32768) should not be confused with regular files such as redir.exe.

The program intercepts Internet Explorer URL addresses, the captured addresses can be sent to a webpage, and redirects to another website - omitted on purpose here.

Aliases

Aliases

  • Spyware.Dotcomtoolbar