Home Rogue Websites Thiswebsiteisblocked.com

Thiswebsiteisblocked.com

Posted: August 11, 2010

Thiswebsiteisblocked.com is a malicious browser hijacker which redirects a user to fraudulent web pages selling rogue software. Thiswebsiteisblocked.com is downloaded after the targeted system gets jacked up by a backdoor Trojan. Thiswebsiteisblocked.com will cause Internet connection problems and the inability to visit any other websites. Initially, victims get redirected to fake web page which notifies the user about the Internet attack. This false warning page redirects to a web page designed to sell Antivirus 7 rogue anti-spyware. Remove the malware related to this blatant scam using an updated anti-virus kit which can easily detect and terminate computer parasites.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\[UserName]\Desktop\Antivirus7.lnk
    2 %Documents and Settings%\All Users\Start Menu\AV
    3 %Documents and Settings%\All Users\Start Menu\AV\Antivirus7.lnk
    4 %Documents and Settings%\All Users\Start Menu\AV\Uninstall.lnk
    5 %Program Files%\Antivirus7AV
    6 %Program Files%\Antivirus7AV\Antivirus7.exe
    7 %Program Files%\Antivirus7AV\unins000.dat
    8 %Program Files%\Antivirus7AV\unins000.exe
    9 %Program Files%\AV
    10 %Program Files%\AV\Antivirus7.exe
    11 %Program Files%\Common Files\Uninstall
    12 %Program Files%\Common Files\Uninstall\AV
    13 %Program Files%\Common Files\Uninstall\AV\Uninstall.lnk
    14 %WINDOWS%\system32\UpdateCheck.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\EVAACDHKEY_CURRENT_USER\Software\FNULL246HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Antivirus7"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\post platform "WinNT-EVI 25.11.2009"HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{6A23338A-C725-48D0-BA96-B12FDD22DD39}_is1
Loading...