Home Rogue Websites Virusermoverpro.com

Virusermoverpro.com

Posted: September 2, 2009

Virusermoverpro.com is a rogue website sponsoring the fake spyware remover called Antivirus System PRO. To achieve this goal, trojans infiltrate your computer through security vulnerabilities and alter the browser settings, causing web-surfing activities to be interrupted and diverted to the Virusermoverpro.com web page. Once here, your PC is subject to a fraudulent online scan that reports fabricated infection results in order to scare you into purchasing Antivirus System PRO.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %WINDOWS%\sysguard.exe
    2 %WINDOWS%\system32\iehelper.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AvScanHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "system tool"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}
Loading...