Home Malware Programs Browser Hijackers Puresafetyhere.com

Puresafetyhere.com

Posted: February 9, 2008

Puresafetyhere.com, which promotes rogue anti-spyware program VirusHeat, is a malevolent browser hijacker designed for malicious purposes. Puresafetyhere.com is often brought to your computer by various Trojans through browser security cracks. Upon execution, Puresafetyhere.com will change your homepage to www.puresafetyhere.com and redirect it to various malicious websites that are producing and promoting malicious applications. Puresafetyhere.com modifies registry to start at every Windows boot and by doing so, it will annoy you with numerous notifications of imaginary errors every time you turn on your computer. In addition, it can steal your personal and financial information to a remote hacker and slow down your system severely. Puresafetyhere.com is also known to be extremely difficult to eliminate.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 cfqbw.dll
    2 fdpzgi.dll
    3 gtawclv.dll
    4 icmntr.exe
    5 icthis.exe
    6 ictun.exe
    7 icun.exe
    8 isfmdl.dll
    9 isfmm.exe
    10 isfmntr.exe
    11 isfun.exe
    12 Online Security Guide.url
    13 pmmon.exe
    14 pmuninst.exe
    15 Puresafetyhere.com
    16 Security Troubleshooting.url
    17 veptlh.dll
    18 vjxwnn.dll
    19 vmlwp.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70d17a5f-ef27-4295-90f5-20ad6f24834f}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{80ced3d6-ece9-48ba-8df8-2503d8d87c2b}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D61D7E1A-6613-49CA-B6F9-51DB248E209D}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{aa6d4f53-4c8d-4549-84d2-02d584acc4e9}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper objects\{D61D7E1A-6613-49CA-B6F9-51DB248E209D}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}IExplorer Security Plug-inInternet Explorer Secure BarMessenger Service
Loading...