Home Rogue Websites Updateyoursecurity.com

Updateyoursecurity.com

Posted: May 4, 2009

Updateyoursecurity.com is a browser hijacker promoting the fake spyware remover System Security 2009 (also known as System Security). Typically your web-surfing activities become interrupted and you are diverted to the updateyoursecurity.com web page due to trojan viruses infiltrating your system and altering your browser settings. Once here, your computer is subject to a fraudulent online scan, which reports various infections that do not exist, all in order to scare you into purchasing the rogue anti-spyware program the domain is recommending, System Security 2009.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %\Documents and Settings%\All Users\Application Data\00308937\00308937.exe
    2 %\Documents and Settings%\All Users\Application Data\00308937\config.udb
    3 %\Documents and Settings%\All Users\Application Data\00308937\pc00308937ins
    4 %UserProfile%\Desktop\System Security 2009.lnk
    5 %UserProfile%\Start Menu\Programs\System Security\System Security 2009 Support.lnk
    6 %UserProfile%\Start Menu\Programs\System Security\System Security 2009.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\Software\00308937HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "00308937"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}SystemSecurity2009
Loading...