Home Rogue Websites Fullvirusprotection.com

Fullvirusprotection.com

Posted: May 11, 2009

Fullvirusprotection.com is a browser hijacker sponsoring the rogue anti-spyware program called System Security 2009. In order to achieve this goal, trojan viruses infiltrate the computer and alter browser settings, causing web-surfing activities to be diverted to the Fullvirusprotection.com web page. Here your computer is subject to a fake online scan that typically reports various fraudulent infection results. This scheme is used to scare you into purchasing System Security 2009, which will not aid your computer at all.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %\Documents and Settings%\All Users\Application Data\00308937\00308937.exe
    2 %\Documents and Settings%\All Users\Application Data\00308937\config.udb
    3 %\Documents and Settings%\All Users\Application Data\00308937\pc00308937ins
    4 %UserProfile%\Desktop\System Security 2009.lnk
    5 %UserProfile%\Start Menu\Programs\System Security\System Security 2009 Support.lnk
    6 %UserProfile%\Start Menu\Programs\System Security\System Security 2009.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\Software\00308937HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "00308937"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}SystemSecurity2009
Loading...