Home Rogue Websites Homeantivirus2010.com

Homeantivirus2010.com

Posted: August 5, 2009

Homeantivirus2010.com is a rogue website sponsoring the distribution of the fake spyware remover Home Antivirus 2010. To achieve this goal, trojans infiltrate your computer by way of security vulnerabilities and alter the browser settings, causing web-surfing activities to be interrupted and diverted to the Homeantivirus2010.com web page. Once here, your PC is subject to a fake online scan that depicts fabricated infection results in order to scare you into purchasing the rogue spyware remover Home Antivirus 2010.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\All Users\Application Data\ciqudehyri.dll
    2 %Program Files%\Common Files\vivifabyx.dll
    3 %Program Files%\Common Files\ywukynota.com
    4 %Program Files%\HomeAntivirus2010
    5 %Program Files%\HomeAntivirus2010\HomeAntivirus2010.exe
    6 %Program Files%\HomeAntivirus2010\htmlayout.dll
    7 %WINDOWS%\syromeni.bat
    8 %WINDOWS%\system32\_scui.cpl
    9 %WINDOWS%\system32\cepapyx.com

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanelHKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USER\Control Panel\don't load\scui.cplHKEY_CURRENT_USER\Control Panel\don't load\wscui.cplHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Home Antivirus 2010
Loading...