Home Rogue Websites Winpc-antivirus09.com

Winpc-antivirus09.com

Posted: May 20, 2009

Winpc-antivirus09.com is a rogue website sponsoring the fake spyware remover WinPC Antivirus. Affiliated trojans infiltrate the computer system via security holes and alter the browser settings, causing the web-surfing activities to be interrupted and diverted to the Winpc-antivirus09.com web page. Here your PC is subject to a fake online scan that reports fabricated infection results, all in order to scare you into purchasing WinPC Antivirus.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Application Data\winav.exe
    2 %UserProfile%\Desktop\WinPC Antivirus.lnk
    3 %UserProfile%\Start Menu\WinPC Antivirus.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "sysav"HKEY_CURRENT_USER\Software\WinPC AntivirusHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusDisableNotify" = 1HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallDisableNotify" = 1HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "UpdatesDisableNotify" = 1HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USER\Control Panel\don't load "scui.cpl"HKEY_CURRENT_USER\Control Panel\don't load "wscui.cpl"
Loading...