Home Rogue Websites Totalvirushield.com

Totalvirushield.com

Posted: April 28, 2009

Totalvirushield.com is a browser hijacker promoting the rogue anti-spyware application System Security 2009 (or System Security). Typically you hit this domain due to a Trojan that infiltrates your computer through security vulnerabilities and modifies your browser settings, redirecting web-surfing activities to the Totalvirushield.com web page. Once here, your computer is subject to a fake online scan that reports counterfeit infection claims. These are to ensure you become scared enough to purchase and download the fake spyware remover System Security 2009, which will do more harm for your system than help it.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %\Documents and Settings%\All Users\Application Data\00308937\00308937.exe
    2 %\Documents and Settings%\All Users\Application Data\00308937\config.udb
    3 %\Documents and Settings%\All Users\Application Data\00308937\pc00308937ins
    4 %UserProfile%\Desktop\System Security 2009.lnk
    5 %UserProfile%\Start Menu\Programs\System Security\System Security 2009 Support.lnk
    6 %UserProfile%\Start Menu\Programs\System Security\System Security 2009.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\Software\00308937HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "00308937"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}SystemSecurity2009
Loading...