Another piece of malware in the wild

Dec 20, 2007 13:46 GMT  ·  By

In case you got sick of pop-up windows displayed on your desktop, I'm sorry to disappoint you, but another adware infection waits for its turn. DreamPoper is an Internet Explorer browser helper object that attempts to harm the user with all kinds of error messages, displayed when searches on Google or HotBot are detected. The infection received a 33 out of 100 severity scale from 2Spyware.com. But, the interesting aspect of the adware is that it scans the system for security applications such as ZoneAlarm and, in case evidence of such tools is found, it remains inactive in the background in order to avoid detection.

"DreamPopper scans your computer for known firewalls such as ZoneAlarm, Sygate Personal firewall, Kerio firewall and Norton Personal firewall and if these are present on your system, DreamPopper will not make any internet connections that makes its presence known", 2Spyware.com wrote in the security notification published today. "A sign of infection is that you get pop-up windows when searching at google.com and hotbot.com."

In case you got infected with DreamPopper, the removal includes two important steps, as the security company mentions in the advisory. First of all, you have to remove the following registry entries, which are both created by the adware infection:

code
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{7D6EFF5E-11BE-AE5E-34CE-7CC268A3041E}
code
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{7D6EFF5E-11BE-AE5E-34CE-7CC268A3041E}
In addition, you're required to delete dreampopper.dll from your computer. All you need to do is to search the system using the Windows Search function or any other utility you want and delete the DLL file. Most antiviruses should also be able to detect the infection anytime soon, so just remember to update your security tool every once in a while. Just to be on the safe side...