Home Rogue Websites Universal-antivirus.com

Universal-antivirus.com

Posted: May 29, 2009

Universal-antivirus.com is a rogue website sponsoring the fake spyware remover System Security 2009. To achieve this goal, trojans infiltrate your computer via security holes and alter the browser settings, causing web-surfing activities to be diverted to the Universal-antivirus.com web page. Here your PC is subject to a fake online scan that reports various fabricated infection results all in order to intimidate you into purchasing System Security 2009.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Desktop\System Security.lnk
    2 %UserProfile%\Start Menu\Programs\System Security
    3 %UserProfile%\Start Menu\Programs\System Security\System Security.lnk
    4 C:\Documents and Settings\All Users\Application Data\538654387
    5 C:\Documents and Settings\All Users\Application Data\538654387\1632575944.exe
    6 C:\Documents and Settings\All Users\Application Data\538654387\config.udb
    7 C:\Documents and Settings\All Users\Application Data\538654387\init.udb
    8 C:\Documents and Settings\All Users\Application Data\538654387\Languages
    9 C:\Documents and Settings\All Users\Application Data\538654387\Languages\English.lng
    10 C:\Documents and Settings\All Users\Application Data\538654387\Languages\German.lng
    11 C:\Documents and Settings\All Users\Application Data\538654387\Languages\Spanish.lng

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"1632575944"
Loading...