Dregol.com

By GoldSparrow in Browser Hijackers

Threat Scorecard

Ranking: 2,767
Threat Level: 50 % (Medium)
Infected Computers: 32,755
First Seen: March 12, 2015
Last Seen: February 19, 2025
OS(es) Affected: Windows

Dregol.com is a suspicious website that may be linked to a PUP or Potentially Unwanted Program in the form of a Web browser extension. Malware analysts have received numerous complaints involving Dregol.com. Dregol.com may hijack a Web browser, causing a wide variety of problems. PUPs linked to Dregol.com may be very difficult to remove through normal means and may require special steps and the use of a reliable security program capable of dealing with low-level threats and PUPs. If PUPs associated with Dregol.com are not removed correctly, problems may come back when the affected Web browser or computer restarts. The most common way of recognizing issues associated with Dregol.com is because an affected Web browser may direct computer user to Dregol.com, display advertisements associated with Dregol.com, and replace homepage and default search engine with Dregol.com automatically.

The Consequences of Dregol.com and Similar Low Quality Websites

Dregol.com and PUPs associated with Dregol.com are not considered threatening. Unlike viruses, Trojans, worms, rootkits and similar threats, PUPs associated with Dregol.com may cause numerous irritating symptoms but are not destructive or pose a significant security or data risk. Their main purpose is to take over a Web browser in order to expose computer users to advertising material. PUPs like those associated with Dregol.com straddle a fine line. They must be able to expose computer users to advertising material effectively but not be annoying or disruptive enough to force computer users to remove them immediately. Malware analysts consider that all PUPs represent some kind of security risk, either because they expose a computer to additional PUPs or because they may be linked to suspicious websites or threatening content indirectly. Because of this, PUPs linked to Dregol.com should be removed immediately with the help of a reliable, fully updated security program.

Symptoms of PUPs Linked to Dregol.com

PUPs associated with Dregol.com may affect most Web browsers on the market. Malware analysts have noted problems that may be linked to Dregol.com on Internet Explorer, Mozilla Firefox, Safari, Opera and Google Chrome. Some symptoms linked to Dregol.com may include the following:

  1. PUPs associated with Dregol.com may replace the affected Web browser's homepage and default search engine with Dregol.com automatically.
  2. PUPs linked to Dregol.com may lower an affected Web browser's security settings, often making it more vulnerable or susceptible to PUPS and other problems.
  3. PUPs linked to Dregol.com rarely appear by themselves. If a PUP linked to Dregol.com is installed on a computer, it is highly likely that other PUPs are present as well. These are common monetization method for threats attacks. Because of this, additional symptoms that affect the entire operating system or the presence of multiple PUPs that are very hard to remove should be taken seriously, as they may indicate a more serious infection.
  4. PUPs such as Dregol.com may be associated with performance issues on affected Web browsers. Web pages may take much longer than normal to load, and the affected Web browser may freeze or crash frequently.
  5. PUPs linked to Dregol.com are closely related to irritating pop-up messages and advertising material. If unwanted advertisements are inserted into websites viewed on the affected Web browser, it is highly likely that there is a PUP present on the affected Web browser.

To prevent issues with Dregol.com and its associated PUPs, malware analysts advise the use of a reliable security program that is highly up to date. Never install software that you don't trust and when installing any software you should follow the installation process carefully and to opt out of the installation of unrecognized components.

Aliases

4 security vendors flagged this file as malicious.

Anti-Virus Software Detection
Sophos DealPly Updater
Kaspersky not-a-virus:HEUR:AdWare.Win32.DealPly.heur
Symantec WS.Reputation.1
CAT-QuickHeal AdWare.DealPly.OD8

SpyHunter Detects & Remove Dregol.com

File System Details

Dregol.com may create the following file(s):
# File Name MD5 Detections
1. UpdateTask.exe 47265154fb2e939fc82f5ec603b67b2c 4
More files

Registry Details

Dregol.com may create the following registry entry or registry entries:
File name without path
dregol.lnk
http_www.dregol.com_0.localstorage
http_www.dregol.com_0.localstorage-journal
Regexp file mask
%WINDIR%\System32\Tasks\[RANDOM CHARACTERS]Dregol[RANDOM CHARACTERS]
%WINDIR%\Tasks\[RANDOM CHARACTERS]Dregol[RANDOM CHARACTERS].job
SOFTWARE\Classes\AppID\{da3128b1-de9e-4e11-81dc-e12090c8f3b9}
Software\Microsoft\Internet Explorer\DOMStorage\dregol.com
Software\Microsoft\Internet Explorer\DOMStorage\www.dregol.com
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Run_dregol.job
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Run_dregol.job.fp
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Run_dregol
Software\Microsoft\Windows\CurrentVersion\RunOnce\Run_dregol
Software\ProductSetup\Uninstall\0D1C1P1N1F1I
Software\run_dregol
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce\Run_dregol

Directories

Dregol.com may create the following directory or directories:

%ALLUSERSPROFILE%\{73539B90-23D1-4A16-9257-3A9442D5E91A}
%AppData%\Run_dregol
%LOCALAPPDATA%\Run_dregol
%PROGRAMFILES%\Run_dregol
%PROGRAMFILES(x86)%\Run_dregol

URLs

Dregol.com may call the following URLs:

dregol.com

1 Comment

This malware is published in surreptitious versions of CamStudio

Trending

Most Viewed

Loading...