Home Malware Programs Browser Hijackers Thesafetynotes.com

Thesafetynotes.com

Posted: August 7, 2007

Thesafetynotes.com is a computer hijacker, which is a result of Trojan Zlob infection. It hijacks your homepage and redirects your Internet Explorer homepage to "thesafetynotes.com". Then it starts displaying fake Warning messages stating that your computer is in serious danger. It attempts to trick you into purchasing the another Trojan related fake anti-spyware programs such as VirusProtectPro, SpyLocked, MalwareAlarm, MalwareWiped and so on. If your computer is hijacked by thesafetynotes.com, then there is a serious risk to the security of your personal and financial data because thesafetynotes.com transfers back and forth information from the infected PC which makes it a potential for data security risk.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 ckimzeb.dll
    2 dxovx.dll
    3 iesplugin.dll
    4 iesuninst.exe
    5 isaddon.dll
    6 isamini.exe
    7 isamonitor.exe
    8 pmmon.exe
    9 pmsngr.exe
    10 pmuninst.exe
    11 Thesafetynotes.com

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5574E139-F59C-4bee-9A61-150B0D3A16C7}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EB}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6DEEE498-08CC-43F0-BCA0-DBB5A25C9501}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSDNS.MSDNSAppHKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\browsers.StockBarHKEY_LOCAL_MACHINE\SOFTWARE\Classes\browsers.ToolBar.1HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VideoExtensionHKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{84C94803-B5EC-4491-B2BE-7B113E013B77}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5574E139-F59C-4bee-9A61-150B0D3A16C7}
Loading...