Home Malware Programs Trojans Safetyuptodate

Safetyuptodate

Posted: July 6, 2006

Safetyuptodate is a computer hijacker that redirects a user's web browser to www.safetyuptodate.com, pops up warning messages and a warning bubble from the taskbar announcing the computer is infected with spyware and that the user should download a spyware remover. Safetyuptodate only promotes fake anti-spyware products such as SpywareStrike, SpyGuard, PestWiper, SpyAxe, Malware Wipe, and Adware Punisher.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 atmclk.exe
    2 dcomcfg.exe
    3 hp100.tmp
    4 simpole.tlb

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browserhelperHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\rundcomcfg.exe
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}686a161d-5bd1-4999-8832-6393f41e564c
Loading...