Home Rogue Websites Spyware-url.com

Spyware-url.com

Posted: October 26, 2009

Spyware-url.com is a malicious website, which is used to promote the rogue anti-spyware program Alpha Antivirus. Users may be redirected to Spyware-url.com which is a result of browser hijacking, accomplished by trojans which change the browser settings on the affected user's computer. The user is redirected to the URL named Spyware-url.com/block.php. The page is a popup, which announces the user that the website being browsed at the particular point in time is not secure, and encourages the user to buy Alpha Antivirus in order to fix flaws. Users are strongly advised not to rely on this website and remove Alpha Antivirus immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 AlphaAntivirus.exe
    2 AlphaAV.exe
    3 msnaoladdon.dll
    4 ndisapi.dll
    5 NetFilter.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Alpha AntivirusHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Alpha Antivirus”HKEY_LOCAL_MACHINE\SOFTWARE\Alpha AntivirusHKEY..\..\..\..{RegistryKeys}%UserProfile%\Desktop\Alpha Antivirus.lnkHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Alpha Antivirus
Loading...