Home Rogue Websites Netspywarescan.com

Netspywarescan.com

Posted: December 17, 2010

Netspywarescan.com is a rogue website that hijacks web browsers and redirects computer users to this corrupt URL. Intitially the system will be attacked by Trojans which trespass on the targeted computer totally undetected before modifying the browser settings. Netspywarescan.com welcomes its visitors with misleading advertising of its affiliated rogue anti-spyware called AntiSpyware Pro 2009. AntiSpyware Pro 2009 is a rogue spyware remover that propagates via trojans and hijackers to trick people into purchasing malicious software. Netspywarescan.com forms an integral part of this devious scam; it usually displays a false online scanner which reports fabricated results stating that the machine is infected with malware. According to Netspywarescan.com, these so-called "parasites" cannot be terminated unless and until you first purchase AntiSpyware Pro 2009 commercial software which demands payment. Do not get conned into buying AntiSpyware Pro 2009 on netspywarescan.com. Doing so will no doubt disrupt your computer and prove to be a waste of money. Remove the Netspywarescan.com hijacker immediately once it has been detected before you get diverted to this corrupt website with malicious scripts.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\aspro2009.exe
    2 gisyflngpshcvuakv.dll
    3 main.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FDA08241-09F3-2DBE-22B1-5B44B581231C}HKEY_CURRENT_USER\Software\Solt Lake SoftwareHKEY_CURRENT_USER\Software\{EBFF3366-F653-ACA1-0798-E062A58FA824}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDA08241-09F3-2DBE-22B1-5B44B581231C}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{FDA08241-09F3-2DBE-22B1-5B44B581231C}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "mfhsornwnduy"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}uzymaulreqvtfzbe
Loading...