Remove-all-malware.com
Remove-all-malware.com is a rogue website sponsoring the distribution of the fake spyware remover Total Security. To achieve this goal, trojans infiltrate your computer by way of security vulnerabilities and alter the browser settings, causing web-surfing activities to be interrupted and diverted to the Remove-all-malware.com web page. Once here, your PC is subject to a fake online scan that depicts fabricated infection results in order to scare you into purchasing the rogue spyware remover Total Security.
File System Modifications
- The following files were created in the system:
# File Name 1 %Program Files%\Common Files\System\Uninstall 2 %Program Files%\Common Files\System\Uninstall\Uninstall TSC.lnk 3 %Program Files%\TSC 4 %Program Files%\TSC\Sc2C21UvvM.exe 5 %Program Files%\TSC\tsc.exe 6 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\TSC.lnk 7 %UserProfile%\Desktop\TSC.lnk 8 %UserProfile%\Start Menu\TSC 9 %UserProfile%\Start Menu\TSC\Help.lnk 10 %UserProfile%\Start Menu\TSC\Registration.lnk 11 %UserProfile%\Start Menu\TSC\TSC.lnk 12 %WINDOWS%\system32\winsource.dll
Registry Modifications
- The following newly produced Registry Values are:
HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\1FD92E3F7C34799BFB075C41DA05D1FEHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "1FD92E3F7C34799BFB075C41DA05D1FE"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = "1"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = "1"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D263FA6D-84CC-48A8-9AF6-C664362B7A5B}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{D263FA6D-84CC-48A8-9AF6-C664362B7A5B}
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.