Home Rogue Websites Superiorinternetsecurity.com

Superiorinternetsecurity.com

Posted: May 18, 2009

Superiorinternetsecurity.com is a rogue website hosting the fake spyware remover called System Security 2009. Typically, Superiorinternetsecurity.com hijacker infiltrates the PC via security exploits using affiliated trojans and attempts to alter the browser settings, causing web-surfing activities to be diverted to the Superiorinternetsecurity.com webpage. This is usually accompanied by a fake online scan that reports numerous false infection results through annoying pop-up windows, all in order to coerce you into purchasing the System Security 2009 fake anti-spyware software.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %\Documents and Settings%\All Users\Application Data\00308937\00308937.exe
    2 %\Documents and Settings%\All Users\Application Data\00308937\config.udb
    3 %\Documents and Settings%\All Users\Application Data\00308937\pc00308937ins
    4 %UserProfile%\Desktop\System Security 2009.lnk
    5 %UserProfile%\Start Menu\Programs\System Security\System Security 2009 Support.lnk
    6 %UserProfile%\Start Menu\Programs\System Security\System Security 2009.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\Software\00308937HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "00308937"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}SystemSecurity2009
Loading...