This is the family description for the Iehlpr family of adware.
Installation
During installation, a DLL is dropped at:
- %appdata%\Microsoft\[...]
Where [...] is a directory that varies depending on the variant.
The name of the dropped DLL file varies, and observed names are "UserData" and "IEHelper". The file name uses the following format:
Where **** is a 4-digit number, such as 5057.
Once dropped, the DLL is registered as a Browser Helper Object (BHO) in Microsoft Internet Explorer.
Activity
When active, the program displays advertisements while the user is browsing. It will also attempt to connect to a remote server.
Network Connections
Attempts to connect to: