Browsersecurecheck.com
Browsersecurecheck.com is a malicious browser hijacker which redirects a user to fraudulent web pages selling rogue software. Browsersecurecheck.com is downloaded after the targeted system gets jacked up by a backdoor Trojan. Browsersecurecheck.com will cause Internet connection problems and the inability to visit any other websites. Initially, victims get redirected to Browsersecurecheck.com/block.php which notifies the user about the Internet attack. This false warning page redirects to a web page designed to sell Antivirus 7 rogue anti-spyware. Remove the malware related to this blatant scam using an updated anti-virus kit which can easily detect and terminate computer parasites.
File System Modifications
- The following files were created in the system:
# File Name 1 %Documents and Settings%\[UserName]\Desktop\Antivirus7.lnk 2 %Documents and Settings%\All Users\Start Menu\AV 3 %Documents and Settings%\All Users\Start Menu\AV\Antivirus7.lnk 4 %Documents and Settings%\All Users\Start Menu\AV\Uninstall.lnk 5 %Program Files%\Antivirus7AV 6 %Program Files%\Antivirus7AV\Antivirus7.exe 7 %Program Files%\Antivirus7AV\unins000.dat 8 %Program Files%\Antivirus7AV\unins000.exe 9 %Program Files%\AV 10 %Program Files%\AV\Antivirus7.exe 11 %Program Files%\Common Files\Uninstall 12 %Program Files%\Common Files\Uninstall\AV 13 %Program Files%\Common Files\Uninstall\AV\Uninstall.lnk 14 %WINDOWS%\system32\UpdateCheck.dll
Registry Modifications
- The following newly produced Registry Values are:
HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\EVAACDHKEY_CURRENT_USER\Software\FNULL246HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Antivirus7"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\post platform "WinNT-EVI 25.11.2009"HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{6A23338A-C725-48D0-BA96-B12FDD22DD39}_is1
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.