Home Malware Programs Browser Hijackers Asafepc.com

Asafepc.com

Posted: April 23, 2010

Asafepc.com (or Asafepc.net) is a browser hijacker related to Virus Protector. Asafepc.com redirects hapless users to a fake system scan which churns out false results claiming the PC is infected with viruses. This is a blatant scam to urge users to purchase Virus Protector. Do not fall for this trickery and have all threats associated to asafepc.com and Virus Protector removed immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\[UserName]\Application Data\[random].dll
    2 %Documents and Settings%\[UserName]\Application Data\[random].exe
    3 %Documents and Settings%\[UserName]\Local Settings\Temp\[random].dll
    4 %Documents and Settings%\[UserName]\Local Settings\Temp\[random].exe
    5 %Program Files%\Internet Explorer\[random].dll
    6 %Program Files%\Internet Explorer\[random].exe
    7 %WINDOWS%\[random].dll
    8 %WINDOWS%\[random].exe
    9 %WINDOWS%\system32\[random].dll
    10 %WINDOWS%\system32\[random].exe
    11 %WINDOWS%\system32\drivers\[random].dll
    12 %WINDOWS%\system32\drivers\[random].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Virus Protector"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows "AppInit_DLLs" = "[random].dll"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows "LoadAppInit_DLLs" = "1"
Loading...