Home Rogue Websites Itsecure.microsoft.com

Itsecure.microsoft.com

Posted: July 13, 2009

Itsecure.microsoft.com is a rogue website sponsoring the fake spyware remover called Antivirus System PRO. To achieve this goal, trojans infiltrate your computer through security holes and attempt to alter the browser settings, causing web-surfing activities to become interrupted and diverted to the Itsecure.microsoft.com web page. Once here, your PC is subject to a fake online scan that reports fabricated infection results in order to scare you into purchasing the rogue spyware remover Antivirus System PRO.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %WINDOWS%\sysguard.exe
    2 %WINDOWS%\system32\iehelper.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AvScanHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "system tool"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}
Loading...