Home Rogue Websites InternetSafetyExamine.com

InternetSafetyExamine.com

Posted: March 30, 2009

InternetSafetyExamine.com is a dangerous web page that may encourage the purchase of rogue anti-spyware programs. The System Security program is a rogue anti-spyware program that is heavily advertised on InternetSafetyExamine.com and may be created by the same makers that published the InternetSafetyExamine.com web site.

If you have been redirected to InternetSafetyExamine.com it could be possible that you have a Trojan infection, clicked a malicious link or your web browser was hijacked. In this case it is essential that you scan your system for any parasites so that they may be detected and removed without causing damage to your computer. InternetSafetyExamine.com may promote the purchase of System Security which is not recommended because System Security is a rogue anti-spyware program that does not perform the actions that it promises to do.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %\Documents and Settings%\All Users\Application Data\538654387
    2 %\Documents and Settings%\All Users\Application Data\538654387\1632575944.exe
    3 %\Documents and Settings%\All Users\Application Data\538654387\config.udb
    4 %\Documents and Settings%\All Users\Application Data\538654387\init.udb
    5 %\Documents and Settings%\All Users\Application Data\538654387\Languages
    6 %\Documents and Settings%\All Users\Application Data\538654387\Languages\English.lng
    7 %\Documents and Settings%\All Users\Application Data\538654387\Languages\German.lng
    8 %\Documents and Settings%\All Users\Application Data\538654387\Languages\Spanish.lng
    9 %UserProfile%\Desktop\System Security.lnk
    10 %UserProfile%\Start Menu\Programs\System Security
    11 %UserProfile%\Start Menu\Programs\System Security\System Security.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "1632575944"
Loading...