Home Malware Programs Browser Hijackers Browsersecurecheck.com

Browsersecurecheck.com

Posted: March 11, 2010

Browsersecurecheck.com is a malicious browser hijacker which redirects a user to fraudulent web pages selling rogue software. Browsersecurecheck.com is downloaded after the targeted system gets jacked up by a backdoor Trojan. Browsersecurecheck.com will cause Internet connection problems and the inability to visit any other websites. Initially, victims get redirected to Browsersecurecheck.com/block.php which notifies the user about the Internet attack. This false warning page redirects to a web page designed to sell Antivirus 7 rogue anti-spyware. Remove the malware related to this blatant scam using an updated anti-virus kit which can easily detect and terminate computer parasites.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\[UserName]\Desktop\Antivirus7.lnk
    2 %Documents and Settings%\All Users\Start Menu\AV
    3 %Documents and Settings%\All Users\Start Menu\AV\Antivirus7.lnk
    4 %Documents and Settings%\All Users\Start Menu\AV\Uninstall.lnk
    5 %Program Files%\Antivirus7AV
    6 %Program Files%\Antivirus7AV\Antivirus7.exe
    7 %Program Files%\Antivirus7AV\unins000.dat
    8 %Program Files%\Antivirus7AV\unins000.exe
    9 %Program Files%\AV
    10 %Program Files%\AV\Antivirus7.exe
    11 %Program Files%\Common Files\Uninstall
    12 %Program Files%\Common Files\Uninstall\AV
    13 %Program Files%\Common Files\Uninstall\AV\Uninstall.lnk
    14 %WINDOWS%\system32\UpdateCheck.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\EVAACDHKEY_CURRENT_USER\Software\FNULL246HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Antivirus7"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\post platform "WinNT-EVI 25.11.2009"HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{6A23338A-C725-48D0-BA96-B12FDD22DD39}_is1
Loading...