Home Malware Programs Browser Hijackers Securitypills.com

Securitypills.com

Posted: March 19, 2008

Securitypills.com is a dangerous website from the Trojan.Zlob family. Securitypills.com promotes corrupt anti-spyware programs in hopes of profiting from gullible computer users. Once you enter Securitypills.com, it will hijack your browser and redirect it to other malicious websites to purchase rogue anti-spyware programs.

Securitypills.com will also display misleading messages of virus threats that can only be eliminated if you purchase rogue anti-spyware program. Securitypills.com may prove dangerous to your security and privacy and, therefore, should be avoided at all costs. If Securitypills.com has already infected your machine, we strongly recommend you to scan your system for Zlob and other possible infections. Securitypills.com advertises rogue anti-spyware programs such as VirusHeat, Win SpyKiller and AntiSpyware Shield.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 1205289674.dll
    2 altvxvm.dll
    3 antiviirus.exe
    4 antzozc.dll
    5 apdqnxp.dll
    6 bokpkov.dll
    7 btrklfr.dll
    8 dfrep.dll
    9 dkxrstqqgr.dll
    10 dtjby.dll
    11 enlfxgw.dll
    12 eulbn.dll
    13 findsiteonline.dll
    14 fsehfcu.dll
    15 G5-tmp.exe
    16 hdtip.dll
    17 icmntr.exe
    18 icthis.exe
    19 ictmdl.dll
    20 ictun.exe
    21 icun.exe
    22 iinqyl.dll
    23 isfmdl.dll
    24 isfmm.exe
    25 isfmntr.exe
    26 isfun.exe
    27 jrpkmgh.dll
    28 laf1.exe
    29 msmsgs.exe
    30 nczupfw.dll
    31 nvctrl.exe
    32 ofcpi.dll
    33 pmuninst.exe
    34 qhcvdw.dll
    35 sbmdl.dll
    36 sbmntr.exe
    37 sbsm.exe
    38 sbun.exe
    39 scit.exe
    40 scm.exe
    41 scu.exe
    42 sysdivx.dll
    43 uimcu.dll
    44 uninst.exe
    45 vipextgpk.dll
    46 vipextnog.dll
    47 vipextpxm.dll
    48 voipwet.dll
    49 wamdl.dll
    50 waun.exe
    51 werbetlrw.dll
    52 werbetpwg.dll
    53 werbettxf.dll
    54 wowlze.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70d17a5f-ef27-4295-90f5-20ad6f24834f}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{80ced3d6-ece9-48ba-8df8-2503d8d87c2b}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D61D7E1A-6613-49CA-B6F9-51DB248E209D}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{aa6d4f53-4c8d-4549-84d2-02d584acc4e9}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper objects\{D61D7E1A-6613-49CA-B6F9-51DB248E209D}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}IExplorer Security Plug-inInternet Explorer Secure BarMessenger Service
Loading...