Dregol.com

By GoldSparrow in Browser Hijackers

Threat Scorecard

Ranking: 2,704
Threat Level: 50 % (Medium)
Infected Computers: 32,055
First Seen: March 12, 2015
Last Seen: September 21, 2023
OS(es) Affected: Windows

Dregol.com is a suspicious website that may be linked to a PUP or Potentially Unwanted Program in the form of a Web browser extension. Malware analysts have received numerous complaints involving Dregol.com. Dregol.com may hijack a Web browser, causing a wide variety of problems. PUPs linked to Dregol.com may be very difficult to remove through normal means and may require special steps and the use of a reliable security program capable of dealing with low-level threats and PUPs. If PUPs associated with Dregol.com are not removed correctly, problems may come back when the affected Web browser or computer restarts. The most common way of recognizing issues associated with Dregol.com is because an affected Web browser may direct computer user to Dregol.com, display advertisements associated with Dregol.com, and replace homepage and default search engine with Dregol.com automatically.

The Consequences of Dregol.com and Similar Low Quality Websites

Dregol.com and PUPs associated with Dregol.com are not considered threatening. Unlike viruses, Trojans, worms, rootkits and similar threats, PUPs associated with Dregol.com may cause numerous irritating symptoms but are not destructive or pose a significant security or data risk. Their main purpose is to take over a Web browser in order to expose computer users to advertising material. PUPs like those associated with Dregol.com straddle a fine line. They must be able to expose computer users to advertising material effectively but not be annoying or disruptive enough to force computer users to remove them immediately. Malware analysts consider that all PUPs represent some kind of security risk, either because they expose a computer to additional PUPs or because they may be linked to suspicious websites or threatening content indirectly. Because of this, PUPs linked to Dregol.com should be removed immediately with the help of a reliable, fully updated security program.

Symptoms of PUPs Linked to Dregol.com

PUPs associated with Dregol.com may affect most Web browsers on the market. Malware analysts have noted problems that may be linked to Dregol.com on Internet Explorer, Mozilla Firefox, Safari, Opera and Google Chrome. Some symptoms linked to Dregol.com may include the following:

  1. PUPs associated with Dregol.com may replace the affected Web browser's homepage and default search engine with Dregol.com automatically.
  2. PUPs linked to Dregol.com may lower an affected Web browser's security settings, often making it more vulnerable or susceptible to PUPS and other problems.
  3. PUPs linked to Dregol.com rarely appear by themselves. If a PUP linked to Dregol.com is installed on a computer, it is highly likely that other PUPs are present as well. These are common monetization method for threats attacks. Because of this, additional symptoms that affect the entire operating system or the presence of multiple PUPs that are very hard to remove should be taken seriously, as they may indicate a more serious infection.
  4. PUPs such as Dregol.com may be associated with performance issues on affected Web browsers. Web pages may take much longer than normal to load, and the affected Web browser may freeze or crash frequently.
  5. PUPs linked to Dregol.com are closely related to irritating pop-up messages and advertising material. If unwanted advertisements are inserted into websites viewed on the affected Web browser, it is highly likely that there is a PUP present on the affected Web browser.

To prevent issues with Dregol.com and its associated PUPs, malware analysts advise the use of a reliable security program that is highly up to date. Never install software that you don't trust and when installing any software you should follow the installation process carefully and to opt out of the installation of unrecognized components.

Aliases

4 security vendors flagged this file as malicious.

Anti-Virus Software Detection
Sophos DealPly Updater
Kaspersky not-a-virus:HEUR:AdWare.Win32.DealPly.heur
Symantec WS.Reputation.1
CAT-QuickHeal AdWare.DealPly.OD8

SpyHunter Detects & Remove Dregol.com

File System Details

Dregol.com may create the following file(s):
# File Name MD5 Detections
1. UpdateTask.exe e64c85b392c7548f3452573e715a1ca8 21
2. UpdateTask.exe afd7f327fcdcc341007760f9f39f951f 20
3. UpdateTask.exe fcd1a5086bba65642775d3d2a27e50ee 18
4. UpdateTask.exe 4ce487ff63247ca2bb9f372bede256de 17
5. UpdateTask.exe 0811ab94367ce4c41276e7ae547c462e 15
6. UpdateTask.exe 67aee779e4160fa802953d1103e48fb9 13
7. UpdateTask.exe 7773677e419370509b897d7b06b49557 13
8. UpdateTask.exe 0eaa0c4e374fbbd679f258228b1b41b1 12
9. UpdateTask.exe 129db597bf4a73b1f63080258ab1141c 9
10. UpdateTask.exe 9c4f9e2bce3a7960346a4e15b97f53c5 9
11. UpdateTask.exe fcbbb6defeae232cd11456efc4fd02b5 8
12. UpdateTask.exe 724bebc13b378d3d7033784f36752ae5 8
13. UpdateTask.exe e028cde73ef74e9732c119e8a9e60d74 7
14. UpdateTask.exe ae0697440e43d6710d59eb0a4e34e1cf 6
15. UpdateTask.exe dbde4a528f3a93a3bd47e4f780453518 6
16. UpdateTask.exe 02dde99d3099dd623bfd1b287d7af897 5
17. UpdateTask.exe d33a6601780bc1a125f896be0e8e3aa9 4
18. UpdateTask.exe 3bd1d14581ddeabdb4d4af4bcdb53953 4
19. UpdateTask.exe a5901243ba8960a81b2c72b5edcb1baa 4
20. UpdateTask.exe fd84f08a2881eeecfb3aa08bb07add05 4
21. UpdateTask.exe e468290a2c4c657ced7297857c35f808 4
22. UpdateTask.exe 47265154fb2e939fc82f5ec603b67b2c 4
23. UpdateTask.exe 22d8921c5c558dfa98219c872164594d 2

Registry Details

Dregol.com may create the following registry entry or registry entries:
File name without path
dregol.lnk
http_www.dregol.com_0.localstorage
http_www.dregol.com_0.localstorage-journal
Regexp file mask
%WINDIR%\System32\Tasks\[RANDOM CHARACTERS]Dregol[RANDOM CHARACTERS]
%WINDIR%\Tasks\[RANDOM CHARACTERS]Dregol[RANDOM CHARACTERS].job
SOFTWARE\Classes\AppID\{da3128b1-de9e-4e11-81dc-e12090c8f3b9}
Software\Microsoft\Internet Explorer\DOMStorage\dregol.com
Software\Microsoft\Internet Explorer\DOMStorage\www.dregol.com
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Run_dregol.job
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Run_dregol.job.fp
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Run_dregol
Software\Microsoft\Windows\CurrentVersion\RunOnce\Run_dregol
Software\ProductSetup\Uninstall\0D1C1P1N1F1I
Software\run_dregol
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce\Run_dregol

Directories

Dregol.com may create the following directory or directories:

%ALLUSERSPROFILE%\{73539B90-23D1-4A16-9257-3A9442D5E91A}
%AppData%\Run_dregol
%LOCALAPPDATA%\Run_dregol
%PROGRAMFILES%\Run_dregol
%PROGRAMFILES(x86)%\Run_dregol

URLs

Dregol.com may call the following URLs:

http://dregol.com/?

1 Comment

This malware is published in surreptitious versions of CamStudio

Trending

Most Viewed

Loading...