Elvdeng

By SpideyMan in Viruses

Win32/Elvdeng.D is part of the Win32/Elvdeng group of Trojans. These Trojans, of Chinese origin, are designed to make changes in the most widely-used Internet browsers. Some of these changes include changing the home page and redirecting browsing. Win32/Elvdeng.D can also open the browser without the computer user's authorization, open multiple browser windows, and create icons on the desktop that direct a computer user to a specific website. If you suspect that Win32/Elvdeng.D is inside your computer system, remove Win32/Elvdeng.D immediately with a reliable anti-virus tool.
 

The Most Common Effects of Win32/Elvdeng.D

Win32/Elvdeng.D is engineered to affect mainly Internet browsers. Here is a list of Win32/Elvdeng.D's most common effects.

- Win32/Elvdeng.D makes changes in your Internet browser's preferences and settings. It will modify the registry so that Internet Explorer's start page is different, usually redirecting to an attack website. Win32/Elvdeng.D has a list of the most popular web browsers. It will monitor the user's computer for any browsers on its list. Then Win32/Elvdeng.D will wait for the computer user to open any of these browsers. When he/she does it, Win32/Elvdeng.D will stop that process and start one of Win32/Elvdeng.D's own, directed to a page of Win32/Elvdeng.D's choice. Win32/Elvdeng.D has multiple methods for redirecting traffic to the malware sites Win32/Elvdeng.D is promoting. In the end, the result will always be that Win32/Elvdeng.D's chosen URLs will substitute any websites opened by the computer user.

- Win32/Elvdeng.D opens browser processes and windows without authorization. While it is installing, Win32/Elvdeng.D will open Internet Explorer and enter an attack website. This Trojan has also been known to open multiple browser windows simultaneously.

- One of the things that characterize Win32/Elvdeng.D is that it will create a shortcut on the desktop that named "taobao special.url" in Chinese characters. This desktop link will take the computer user to the taobao.html file on the xihao.net server. This website has been known to infect the computer with additional Trojans and rogue anti-spyware program.
 

Steps You Can Take to Prevent a Win32/Elvdeng.D Infection on Your Computer

Trojan infections can be annoying at best. In the worst cases, they can cause irreparable damage to your computer. Trojans can also allow hackers to steal your personal information and even use your computer for their own purposes. Follow these easy steps to make sure you are protected:

  1. Protect your computer and network with a firewall. A good firewall with the proper settings will help stop most common intrusions into your privacy. Also, use an anti-virus tool from a reliable manufacturer and keep it updated with the latest definitions.
  2. Make sure that all of your software is properly updated. Trojans exploit security breaches on your computer. Updates are usually released to help patch up these possible exploits. Make sure that you download any updates directly from the manufacturer. Third-party websites are often a source of infection themselves.
  3. Be careful about who uses your computer. The best thing to do is to have different user accounts on your computer and to limit what each account can do. Limiting what users can do on your computer also helps avoid the possibility of you causing damage inadvertently to your own computer.
  4. Use common sense when browsing. This means not opening email attachments from unknown senders, not clicking on unknown links, never downloading files you don't know, and avoiding illegal or pirated software.
  5. Most of all, be smart. Hackers use social engineering to exploit human behavior rather than limiting themselves to attacking your computer. Choose passwords that are difficult to guess and break with brute force. Also, make sure that you treat Internet browsing with caution. Most importantly, don't believe everything you read. Treat the Internet as an extension of the real world. Realize that you are as vulnerable to theft and scams from computer criminals as you would be from physical people on the street.

File System Details

Elvdeng may create the following file(s):
# File Name Detections
1. sstatic.exe
2. sysinit.exe
3. uninstall.exe
4. hook.dll
5. scvhost.exe
6. taobao.ico
7. config.ini
8. uninstall.dat

Registry Details

Elvdeng may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard.1\SearchQUIEHelper.DNSGuard
Explorer\HKEY_LOCAL_MACHINE\SOFTWARE\Classes

Trending

Most Viewed

Loading...