Home Rogue Websites Live-windowsantivirus.com

Live-windowsantivirus.com

Posted: February 19, 2010

Live-windowsantivirus.com is a rogue website that promotes a rogue anti-spyware program called XP Internet Security 2010 although the actual inscription on the site is Windows Defender 2010. If your browser is redirected to Live-windowsantivirus.com your system is most likely infected with Trojans related to the XP Internet Security 2010 cyber-scam. XP Internet Security 2010 wants you to spend money and does this by using scare tactics. Live-windowsantivirus.com produces a fake system scam which claims the system is infected with malware. Then you will be bombarded by warnings urging the purchase of a license for XP Internet Security 2010 to remove these alleged threats. Do not fall for this blatant scam and have all threats associated to XP Internet Security 2010 removed immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Local Settings\Application Data\av.exe
    2 %UserProfile%\Local Settings\Application Data\WRblt8464P

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-modeHKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Internet Explorer\iexplore.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = "1"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = "1"HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1"HKEY_CLASSES_ROOT\secfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1"
Loading...