Home Malware Programs Rogue Anti-Spyware Programs Microantivirus2009.com

Microantivirus2009.com

Posted: September 12, 2008

Microantivirus2009.com is a rogue website, home of rogue anti-spyware programs Micro Antivirus 2009. Microantivirus2009.com is known to advertise Micro Antivirus 2009 as a legitimate softwares to remove supposed spyware threats from your computer system. Once you download Micro Antivirus 2009, it will prompt popups and misleading notifications stating you're infected with spyware. If you click on any of these messages, you'll be redirected to Microantivirus2009.com where you can purchase Micro Antivirus 2009's "licensed" program. Micro Antivirus 2009's trial version is also able to run a fake computer system scan and display a list of security risks supposedly found in your computer system. Micro Antivirus 2009 has the ability to recreate itself after reboot and its "System scan" messages may continue pop up on your task manager. It is recommended that you do not download or install any programs that Microantivirus2009.com provides on its website.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 cfqbw.dll
    2 fdpzgi.dll
    3 gtawclv.dll
    4 iesplugin.dll
    5 iesuninst.exe
    6 isaddon.dll
    7 isamini.exe
    8 isamonitor.exe
    9 khtbpdl.dll
    10 Online Security Guide.url
    11 pmmon.exe
    12 pmsngr.exe
    13 pmuninst.exe
    14 Security Troubleshooting.url
    15 veptlh.dll
    16 vjxwnn.dll
    17 vmlwp.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70d17a5f-ef27-4295-90f5-20ad6f24834f}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{80ced3d6-ece9-48ba-8df8-2503d8d87c2b}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D61D7E1A-6613-49CA-B6F9-51DB248E209D}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{aa6d4f53-4c8d-4549-84d2-02d584acc4e9}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper objects\{D61D7E1A-6613-49CA-B6F9-51DB248E209D}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}IExplorer Security Plug-inInternet Explorer Secure BarMessenger Service
Loading...