Home Rogue Websites Stop-Spyware.net

Stop-Spyware.net

Posted: August 31, 2009

Stop-Spyware.net is a rogue website sponsoring the fake spyware remover Spyware Crusade. It achieves this goal by infiltrating your computer with trojans via security holes and altering the browser settings, causing web-surfing activities to be interrupted and diverted to the Stop-Spyware.net web page. Once here, your PC is subject to a fake online scan that reports back fraudulent infection results in order to scare you into purchasing the Spyware Crusade malicious program.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\All Users\Application Data\Spyware-Crusade
    2 %Documents and Settings%\All Users\Start Menu\Programs\Spyware-Crusade
    3 %Program Files%\LabelCommand
    4 %Program Files%\Spyware-Crusade
    5 %System Root%\Samples
    6 %User Profile%\Local Settings\Temp

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Spyware-Crusade"HKEY_CURRENT_USER\Software\Spyware-CrusadeHKEY_LOCAL_MACHINE\SOFTWARE\Spyware-CrusadeHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Spyware-Crusade
Loading...