Home Rogue Websites Virussweeper-scanvirus.net

Virussweeper-scanvirus.net

Posted: April 15, 2009

An aggressive browser hijacker, Virussweeper-scanvirus.net promotes the rogue anti-spyware program Virus Sweeper, and in order to sponsor such a diabolical application, Virussweeper-scanvirus.net infiltrates your system with a Trojan virus that modifies your browser settings in order to redirect any and all web-surfing activities to their corrupted domain.

Once you have found your way to Virussweeper-scanvirus.net - whether intentionally or without consent - a false online scanner will check your system for any infections, and what do you know? The scanner will report numerous parasites and urge you to purchase Virus Sweeper in order to combat these deadly - and completely fictitious - viruses. Do not fall for this scam, and remove Virussweeper-scanvirus.net immediately upon detection.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %\Documents and Settings%\All Users\Application Data\7c69f0c
    2 %\Documents and Settings%\All Users\Application Data\7c69f0c\LoopSystem
    3 %\Documents and Settings%\All Users\Application Data\7c69f0c\LoopSystem\vd952342.bd
    4 %\Documents and Settings%\All Users\Application Data\7c69f0c\VSweep.exe
    5 %\Documents and Settings%\All Users\Application Data\LoopSystem
    6 %\Documents and Settings%\All Users\Application Data\LoopSystem\swcfg.ini
    7 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Virus Sweeper.lnk
    8 %UserProfile%\Application Data\Virus Sweeper
    9 %UserProfile%\Application Data\Virus Sweeper\Instructions.ini
    10 %UserProfile%\Desktop\Virus Sweeper.lnk
    11 %UserProfile%\Recent\ANTIGEN.drv
    12 %UserProfile%\Recent\cb.dll
    13 %UserProfile%\Recent\CLSV.dll
    14 %UserProfile%\Recent\energy.exe
    15 %UserProfile%\Recent\exec.dll
    16 %UserProfile%\Recent\fix.sys
    17 %UserProfile%\Recent\PE.exe
    18 %UserProfile%\Recent\PE.sys
    19 %UserProfile%\Recent\ppal.tmp
    20 %UserProfile%\Recent\snl2w.drv
    21 %UserProfile%\Recent\tjd.exe
    22 %UserProfile%\Recent\tjd.tmp
    23 %UserProfile%\Start Menu\Programs\Virus Sweeper.lnk
    24 %UserProfile%\Start Menu\Virus Sweeper.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "97680312703"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Virus Sweeper"HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}HKEY_CLASSES_ROOT\VSweep.DocHostUIHandler
Loading...