Home Rogue Websites Hqpcscanner.com

Hqpcscanner.com

Posted: August 24, 2009

Hqpcscanner.com is a rogue website sponsoring the distribution of the fake spyware remover SaveSoldier. To achieve this goal, trojans infiltrate your computer by way of security vulnerabilities and alter the browser settings, causing web-surfing activities to be interrupted and diverted to the Hqpcscanner.com web page. Once here, your PC is subject to a fake online scan that depicts fabricated infection results in order to scare you into purchasing the rogue spyware remover SaveSoldier.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\\All Users\Start Menu\Programs\SaveSoldier\1 SaveSoldier.lnk
    2 %Documents and Settings%\\All Users\Start Menu\Programs\SaveSoldier\2 Homepage.lnk
    3 %Documents and Settings%\\All Users\Start Menu\Programs\SaveSoldier\3 Uninstall.lnk
    4 %Documents and Settings%\All Users\Desktop\SaveSoldier.lnk
    5 %Documents and Settings%\s\All Users\Start Menu\Programs\SaveSoldier
    6 %Program Files%\SaveSoldier Software
    7 %Program Files%\SaveSoldier Software\SaveSoldier
    8 %Program Files%\SaveSoldier Software\SaveSoldier\data.bin
    9 %Program Files%\SaveSoldier Software\SaveSoldier\license.txt
    10 %Program Files%\SaveSoldier Software\SaveSoldier\SaveSoldier.exe
    11 %Program Files%\SaveSoldier Software\SaveSoldier\SaveSoldierSvc.exe
    12 %Program Files%\SaveSoldier Software\SaveSoldier\uninstall.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "SaveSoldier"HKEY_CURRENT_USER\Software\SaveSoldierHKEY_LOCAL_MACHINE\SOFTWARE\SaveSoldierHKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SaveSoldierSvcHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SaveSoldierSvcHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}SaveSoldier
Loading...