Home Rogue Websites Pc-inspector.microsoft.com

Pc-inspector.microsoft.com

Posted: March 15, 2010

Pc-inspector.microsoft.com is a malicious website which promotes Antivirus Soft rogue anti-spyware. The hackers behind the Antivirus Soft scam use Trojans to hijack the browser and redirect users to Pc-inspector.microsoft.com, which produces a fake system scan. The fake scan will show bogus results claiming that the system is infected with malware. Do not fall for this trickery. Hackers want you to pay for a copy of Antivirus Soft "to remove the threats". Do not click on anything you see on Pc-inspector.microsoft.com, instead use a reliable anti-spyware program to remove Pc-inspector.microsoft.com and the Trojans related to Antivirus Soft.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]sftav.exe
    2 %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]sysguard.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AvScanHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5555"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random string]"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random string]"
Loading...