Home Rogue Websites Antivirus-online-pro-scan.com

Antivirus-online-pro-scan.com

Posted: April 28, 2009

Antivirusonlineproscan.com is a browser hijacker that promotes the infamus rogue anti-spyware program called Total Security (also known as Total Security Protection Center). A trojan virus infiltrates your computer through security exploits and modifies browser settings, in order to forcefully redirect any web-surfing activities directly to the Antivirusonlineproscan.com web page. Once here, you will be subject to intense and obsessive adware aiming to mislead you into thinking Total Security is a legitimate tool that you will need to protect your system, persuading you to purchase and download it. However, Total Security is not to be trusted, and neither is Antivirusonlineproscan.com.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Program Files%\Common Files\System\Uninstall
    2 %Program Files%\Common Files\System\Uninstall\Uninstall TSC.lnk
    3 %Program Files%\TSC
    4 %Program Files%\TSC\Sc2C21UvvM.exe
    5 %Program Files%\TSC\tsc.exe
    6 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\TSC.lnk
    7 %UserProfile%\Desktop\TSC.lnk
    8 %UserProfile%\Start Menu\TSC
    9 %UserProfile%\Start Menu\TSC\Help.lnk
    10 %UserProfile%\Start Menu\TSC\Registration.lnk
    11 %UserProfile%\Start Menu\TSC\TSC.lnk
    12 %WINDOWS%\system32\winsource.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\1FD92E3F7C34799BFB075C41DA05D1FEHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "1FD92E3F7C34799BFB075C41DA05D1FE"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = "1HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = "1"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D263FA6D-84CC-48A8-9AF6-C664362B7A5B}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{D263FA6D-84CC-48A8-9AF6-C664362B7A5B}
Loading...