TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
TROJ_BRDUPDATE.E
Overview

Malware type: Trojan

Aliases: Trojan-Downloader.Win32.Braidupdate.d (Kaspersky), Adware.BrowserAid (Symantec), TR/Drop.Braidup.D.2 (Avira), Troj/Brdupd-A (Sophos),

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 95, 98, ME, NT, 2000, XP

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

Low

Distribution potential:

Low

Description: 

This Trojan DLL may be installed by other malware in the Windows system folder using the file name STLB2.DLL.

Upon execution, it creates a registry entry that ensures its automatic execution at every Windows startup. It then registers itself as a Browser Helper Object (BHO) by creating several registry keys and entries.

As a Browser Helper Object, it allows attackers to customize and control Internet Explorer. Created BHOs have access to all the events and properties of the current browsing session. Hence, it may be used to gather information on the machine for use by other malware.

This BHO hijacks the search toolbar of Internet Explorer, preventing users from accessing the search toolbar. Activating the search toolbar by clicking Views>Toolbars>Search in Internet Explorer on affected systems only shows a blank pane.

It runs on Windows 95, 98, ME, NT, 2000, and XP.

For additional information about this threat, see:
Solution
Technical Details

Description created: Jan. 3, 2005 5:07:32 AM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.