Content

Downloader-BR

Type
Program
SubType
-
Discovery Date
03/22/2003
Minimum DAT
4254 (03/26/2003)
Updated DAT
4320 (01/28/2004)
Minimum Engine
5.1.00
Description Added
01/20/2004
Description Modified
01/20/2004 10:20 AM (PT)

Tab Navigation

Characteristics

This is a generic description, because there are more than one variant covered by this detection name.

--- Update January 20, 2004 ---
Detection of Porndial-155 has been merged into this driver, starting with 4318DATs. Prior DATs identify the DLOAD.EXE as Porndial-155.ldr and COMLOAD.DLL as Porndial-155.


This is not a virus or trojan. It is a potentially unwanted program. 

When executed, this downloader application (DLOAD.EXE) attempts to download files via HTTP. The files it tries to download from dload.ipbill.com site are premium rate dialers.

While downloading, it displays a window:

During that time, it downloads and writes a DLL named COMLOAD.DLL to the %windir%\System32 folder and once completed, the DLL gets registered.

These registry keys are created by the DLL:

  •  HKEY_CLASSES_ROOT\Comload.loader
  •  HKEY_CLASSES_ROOT\Comload.loader.1
  •  HKEY_CLASSES_ROOT\Comload.loader2
  •  HKEY_CLASSES_ROOT\Comload.loader2.1

Aliases

Aliases

  • Porndial-155
  • Porndial-155.ldr