Home Rogue Websites Barracuda-antivirus.com

Barracuda-antivirus.com

Posted: June 12, 2009

Barracuda-antivirus.com is a rogue website sponsoring the fake spyware remover Barracuda Antivirus. In order to achieve this goal, trojans infiltrate your computer through security vulnerabilities and alter the browser settings, causing web-surfing activities to be interrupted and diverted to the Barracuda-antivirus.com web page. Once here, your PC is subject to a fake online scan that reports fabricated infection results in order to scare you into purchasing Barracuda Antivirus.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\Barracuda Antivirus\Antivirussystempro.exe
    2 %ProgramFiles%\Barracuda Antivirus\conf.cfg
    3 %ProgramFiles%\Barracuda Antivirus\mbase.vdb
    4 %ProgramFiles%\Barracuda Antivirus\quarantine.vdb
    5 %ProgramFiles%\Barracuda Antivirus\queue.vdb
    6 %ProgramFiles%\Barracuda Antivirus\uninstall.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Barracuda AntivirusHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Barracuda Antivirus"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad "ieModule"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Barracuda Antivirus
Loading...