Home Rogue Websites Browsersecurityaddon.com

Browsersecurityaddon.com

Posted: November 30, 2009

Browsersecurityaddon.com is a corrupt website/domain that jeopardizes web browsing and computer activities. Browsersecurityaddon.com advertises Antivir Antivirus malware schemes. Browsersecurityaddon.com produces a fake warning page that claims web security has been breached. Clicking on a Browsersecurityaddon.com button will take you to another page where you will be persistently asked to install Antivir Antivirus. Do not fall for Browsersecurityaddon.com's warnings and do not install and buy Antivir because it is scam. Browsersecurityaddon.com will swindle you out of your credit card savings and make surfing the web virtually impossible. If infected with Browsersecurityaddon.com or Antivir Antivirus, you should take appropriate measures to remove them from the infected computer.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\All Users\Start Menu\AV
    2 %Documents and Settings%\All Users\Start Menu\AV\Antivir.lnk
    3 %Documents and Settings%\All Users\Start Menu\AV\Uninstall.lnk
    4 %Program Files%\AV
    5 %Program Files%\AV\antivir.exe
    6 %Program Files%\Common Files\Uninstall
    7 %Program Files%\Common Files\Uninstall\AV
    8 %Program Files%\Common Files\Uninstall\AV\Uninstall.lnk
    9 %UserProfile%\Desktop\Antivir.lnk
    10 %WINDOWS%\system32\UpdateCheck.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\EVAACDHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “AV”HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}
Loading...