Home Rogue Websites Prowebantimalware.com

Prowebantimalware.com

Posted: November 30, 2009

Prowebantimalware.com is a rogue website which is also known as a browser hijacker. Prowebantimalware.com supports the rogue Antivir Antivirus. Prowebantimalware.com corrupts the user's online activities by constantly redirecting the browser to a fake online scanner page. Prowebantimalware.com uses malicious trojans to modify the Hosts file and browser configuration on the system.

The computer user will experience random hits to Prowebantimalware.com with a fixed URL appendix that leads to the bogus scanner mentioned above. Prowebantimalware.com also appears to mimic the user's My Computer interface.
It's only after a thorough analysis of Prowebantimalware.com GUI that it becomes obvious it's a fake. The drive names may not be the same as originals, and a bizarre scan progress indicator will run inside the Prowebantimalware.com window. Prowebantimalware.com is a misleading website and should be removed from the system immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\All Users\Start Menu\AV
    2 %Documents and Settings%\All Users\Start Menu\AV\Antivir.lnk
    3 %Documents and Settings%\All Users\Start Menu\AV\Uninstall.lnk
    4 %Program Files%\AV
    5 %Program Files%\AV\antivir.exe
    6 %Program Files%\Common Files\Uninstall
    7 %Program Files%\Common Files\Uninstall\AV
    8 %Program Files%\Common Files\Uninstall\AV\Uninstall.lnk
    9 %UserProfile%\Desktop\Antivir.lnk
    10 %WINDOWS%\system32\UpdateCheck.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\EVAACDHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “AV”HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}
Loading...