Home Malware Programs Browser Hijackers Stopmalwaresite.com

Stopmalwaresite.com

Posted: August 24, 2010

Stopmalwaresite.com is a misleading website that advertises the fake security applications called Antivirus 7 and Antivirus GT. Users that find themselves being frequently redirected to Stopmalwaresite.com are already infected with the trial version of the mentioned fake security applications. These malicious applications will also display fake security notifications that will redirect a victim to Stopmalwaresite.com once clicked on. Users should avoid Stopmalwaresite.com and never purchase anything from this website.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\All Users\Start Menu\AV
    2 %Documents and Settings%\All Users\Start Menu\AV\Antivirus7.lnk
    3 %Documents and Settings%\All Users\Start Menu\AV\Uninstall.lnk
    4 %Program Files%\Antivirus7AV
    5 %Program Files%\Antivirus7AV\Antivirus7.exe
    6 %Program Files%\Antivirus7AV\unins000.dat
    7 %Program Files%\Antivirus7AV\unins000.exe
    8 %Program Files%\AV
    9 %Program Files%\AV\Antivirus7.exe
    10 %Program Files%\Common Files\Uninstall
    11 %Program Files%\Common Files\Uninstall\AV
    12 %Program Files%\Common Files\Uninstall\AV\Uninstall.lnk
    13 %WINDOWS%\system32\UpdateCheck.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\EVAACDHKEY_CURRENT_USER\Software\FNULL246HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ?Antivirus7″HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\post platform ?WinNT-EVI 25.11.2009″HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{6A23338A-C725-48D0-BA96-B12FDD22DD39}_is1

2 Comments

  • matt says:

    Can you help me....I\'m a computer idiot....I have no idea what you are talking about.
    I have \"Malware\" sh*t coming up on my computer all the time.

  • owen carter says:

    malware comes up 98 out of 100 times and I get so frustrated,every thing takes so much time, thank yoiu

Loading...