Spyware Information: 3DoL
This is a Browser Helper Object (BHO). BHO's connect to Internet Explorer while it's running, and share information. BHO's were originally designed to allow Internet Explorer to handle new types of data and to offer new features not originally designed into the product (like search toolbars, for example). But because BHO's have access to all the information about the web sites that you visit (and because BHO's run on your computer and could potentially do anything they want), they have been used by advertising companies and others to track you online.
- Size: 124,216 bytes
- Threat level: Medium (more info...)
- Detections: 1,124 this month: 1
- Author: Unknown
- Appeared: June, 2004
Research
- Method of infection: Very little is known about this infection. It had only been reported by one customer at the time of this article's writing. There are three files associated with it: a BHO and two EXEs. It is not clear how they are distributed.
- Privacy issues: The BHO does not serve a constructive purpose. Because it is watching all web traffic and not providing any features, it may be reasonable to assume that it is storing information on your surfing habits, potentially for later broadcast; or that it is intercepting links of a particular type and doing something with them. It could be used to extend Internet Explorer over protocols that are not safe.
- Security issues: Dissembling the BHOs and EXEs did not yield much. One of the EXEs hides the BHO and installs it, and also morphs itself into a file of a different name (and size!) and stores itself in the Windows folder. The other EXE has unknown effects.
- Stability issues: Testing these files on a Windows 98 machine brought the machine down and we could not bring it up. It had infected Explorer.exe in such a way that it would crash each time the computer started, even in Safe Mode.
Spyware Detection Stats
- Spyware Fingerprints: 91,859
- Detections: 6,792,656
- Detections this Month: 803


