Home Rogue Websites Security-tool2010.com

Security-tool2010.com

Posted: February 15, 2010

Security-tool2010.com (or Security-tool2010.com/online-scanner) is a new Internet hub distributing malware. Security-tool2010.com is a fake scan page promoting the Security Tool rogue anti-spyware program. The trojan viruses accompanying Security Tool 2010 rogue antispyware corrupt the web browser of the infected computer so that users are redirected to Security-tool2010.com/online-scanner. Once here the victim machine will be bombarded with malware. These blackhat methods aim to compell the user to purchase Security Tool, which is in fact useless. Do not fall for this scam and have Security-tool2010.com removed with a proven anti-malware program.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Application Data\4946550101
    2 %UserProfile%\Application Data\4946550101\[random number].bat
    3 %UserProfile%\Application Data\4946550101\[random number].cfg
    4 %UserProfile%\Application Data\4946550101\[random number].exe
    5 %UserProfile%\Desktop\Security Tool.lnk
    6 %UserProfile%\Start Menu\Programs\Security Tool.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Security ToolHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random number]"
Loading...