Home Malware Programs Browser Hijackers Staeshine.com

Staeshine.com

Posted: March 30, 2010

Staeshine.com is a malicious browser hijacker related to the Virus Protector cyber scam. The hackers behind this scam have designed staeshine.com to appear as a system scan webpage which produces bogus results. The results will show that the computer is infected with malware, but this is a blatant lie. Soon the hapless computer user will be bombarded by popup warnings urging the purchase of Virus Protector to remove the so-called threats. Do not fall for this trickery and have staeshine.com and all threats related to Virus Protector removed immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\[UserName]\Application Data\[random].dll
    2 %Documents and Settings%\[UserName]\Application Data\[random].exe
    3 %Documents and Settings%\[UserName]\Local Settings\Temp\[random].dll
    4 %Documents and Settings%\[UserName]\Local Settings\Temp\[random].exe
    5 %Program Files%\Internet Explorer\[random].dll
    6 %Program Files%\Internet Explorer\[random].exe
    7 %WINDOWS%\[random].dll
    8 %WINDOWS%\[random].exe
    9 %WINDOWS%\system32\[random].dll
    10 %WINDOWS%\system32\[random].exe
    11 %WINDOWS%\system32\drivers\[random].dll
    12 %WINDOWS%\system32\drivers\[random].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Virus Protector"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows "AppInit_DLLs" = "[random].dll"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows "LoadAppInit_DLLs" = "1"
Loading...