Home Rogue Websites System-defender.net

System-defender.net

Posted: March 18, 2010

System-defender.net is a rogue website which promotes Antivirus Soft rogue antispyware. Internet users may get redirected to System-defender.net after their computer is infected with Trojans which hijack the browser. System-defender.net runs fake system scans which churn out bogus results claiming the PC is infected with various malware. Hapless users will then be urged to purchase Antivirus Soft to remove these alleged threats. Do not fall for this trickery, it is a blatant scam and Antivirus Soft is a useless product. Use a reliable antivirus program to remove all threats associated with System-defender.net and Antivirus Soft.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]sftav.exe
    2 %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]sysguard.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AvScanHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5555"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random string]"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random string]"
Loading...