Home Rogue Websites Deluxe-Protector.com

Deluxe-Protector.com

Posted: June 5, 2009

Deluxe-protector.com is a rogue website sponsoring the fake spyware remover known as XP Deluxe Protector. To achieve this goal, Trojans infiltrate your computer through security vulnerabilities and alter the browser settings, causing web-surfing activities to be interrupted and diverted to the Deluxe-protector.com web page. Once here, your PC is subject to a fake online scan that displays fabricated infection reports in order to scare you into purchasing Deluxe Protector.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Desktop\XP Deluxe Protector.LNK
    2 %UserProfile%\Start Menu\XP Deluxe Protector.LNK
    3 %UserProfile%\XP Deluxe Protector\xpdeluxe.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\xpprotectHKEY_CURRENT_USER\Software\XP Deluxe Protector
Loading...