Prevalence:

Medium
Name:
Adware.BHO
Type:
Adware
How it spreads:
Malicious Applications
Affected operating:
All versions of the Windows® Operating System
Aliases:
Adware.Win32.BHO.cd, Backdoor-AWQ.b, ADSPY/Thunder
Date of surface:
Mar 24 2007 12:00AM
Symptoms:
XunLeiBHO_001.dll present in the system folder
Description:
This library is dropped in the system folder as ‘XunLeiBHO_001.dll’ by an executable which then registers the DLL and deletes itself. Despite the misleading file name, the DLL is not part of the Thunder Download Manager, but usually comes bundled with piracy tools (patchers and key generators), that install it without any notice.
Upon loading, it submits information about the system it is running on to various addresses, depending on the version.
For disinfection, download and run our free eScan Anti-Virus Toolkit. The utility checks your computer, system registry, and running processes for malicious programs, illegal dialers, and sniffer tools. Note: This tool does not protect your PC in real time.<BR><BR>You can download the eScan Anti-Virus Toolkit utility from the MicroWorld Web site > http://www.escanav.com/english/content/products/MWAV/escan_mwav.asp<BR><BR>Alternatively, you can install MicroWorld’s Internet Security Suite which has real time detection capabilities. You can download and install the product from our eScan download page > http://www.escanav.com/english/content/products/generic_eScan/eScan.asp.