Home Rogue Websites Live-virus-scanner7.com

Live-virus-scanner7.com

Posted: August 28, 2009

Live-virus-scanner7.com is a rogue website sponsoring the distribution of the fake spyware remover Personal Antivirus. To achieve this goal, trojans infiltrate your computer by way of security vulnerabilities and alter the browser settings, causing web-surfing activities to be interrupted and diverted to the Live-virus-scanner7.com web page. Once here, your PC is subject to a fake online scan that depicts fabricated infection results in order to scare you into purchasing the rogue spyware remover Personal Antivirus.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Application Data\Personal Antivirus
    2 %UserProfile%\Application Data\Personal Antivirus\db
    3 c:\Documents and Settings\All Users\Start Menu\Programs\Personal Antivirus
    4 c:\Program Files\Personal Antivirus
    5 c:\Program Files\Personal Antivirus\db
    6 c:\Program Files\Personal Antivirus\Languages

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "PrS"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Personal Antivirus"HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ITGRDENGINEHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ITGrdEngineHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Personal Antivirus_is1
Loading...