Home Rogue Websites Desktop-antivirus.com

Desktop-antivirus.com

Posted: January 15, 2010

Desktop-antivirus.com is a rogue website that may be hosting browser hijackers related to the rogue anti-spyware application called Antivirus Live. Through Desktop-antivirus.com or the domain Desktop-antivirus.com.microsoft.com, a computer can be compromised and automatically redirected to malicious sources.

Desktop-antivirus.com may promote the download of a rogue security application and initiate a scam that forces you to purchase a bogus security program. It is recommended that computer users avoid visiting the domain Desktop-antivirus.com.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\\[UserName]\\Application Data\\[RandomSymbols]\\[Random4Symbols]sysguard.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AvScanHKEY_CURRENT_USER\Software\Microsoft\Windows ScriptHKEY_CURRENT_USER\Software\Microsoft\Windows Script\SettingsHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\AssociationsHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments
Loading...