Home Rogue Websites Onlinespywarescanner.net

Onlinespywarescanner.net

Posted: April 7, 2009

Onlinespywarescanner.net is a malicious hijacker website that promotes the rogue anti-spyware program called AntiSpyware Pro 2009. By becoming infected with a Trojan virus that alters your browser settings, your web-surfing activities are usually interrupted as you are diverted to the Onlinespywarescanner.net web page without authorization. Here is where you are told that your PC may not be safe and that you need a tool to fix it.

This is where AntiSpayware 2009 comes in. By being persuaded by this misleading and malicious domain, you may find yourself purchasing and installing AntiSpyware 2009, which will do nothing to repair or protect your computer from infections. Any and all parasites you are told about by Onlinespywarescanner.net are more than likely fake, attempting to trick you into making this worthless purchase. The most sensible thing to do is removing AntiSpyware Pro 2009 and its hijacker right upon detection.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\All Users\Application Data\Solt Lake Software\Pro Antispyware 2009\aspro2009.exe
    2 gisyflngpshcvuakv.dll
    3 main.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FDA08241-09F3-2DBE-22B1-5B44B581231C}HKEY_CURRENT_USER\Software\Solt Lake SoftwareHKEY_CURRENT_USER\Software\{EBFF3366-F653-ACA1-0798-E062A58FA824}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDA08241-09F3-2DBE-22B1-5B44B581231C}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{FDA08241-09F3-2DBE-22B1-5B44B581231C}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "mfhsornwnduy"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}uzymaulreqvtfzbe
Loading...