Home Rogue Websites Winpcantivirus2010.com

Winpcantivirus2010.com

Posted: May 27, 2009

Winpcantivirus2010.com is a rogue website sponsoring the fake spyware remover WinPC Antivirus. Winpcantivirus2010.com achieves this goal by infiltrating your PC with trojans that alter your browser settings, causing web-surfing activities to be continuously interrupted and diverted to the Winpcantivirus2010.com web page. Here your computer is subject to a fake online scan that reports fabricated and exaggerated infection results, in order to scare you into purchasing WinPC Antivirus.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Application Data\pcantivirus.exe
    2 %UserProfile%\Desktop\WinPC Antivirus.LNK
    3 %UserProfile%\Start Menu\WinPC Antivirus.LNK
    4 C:\Documents and Settings\All Users\Ta1HnnaIasEcfgF.exe
    5 c:\WINDOWS\ieocx.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "sysav"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{96ad72e4-2e2b-4ffc-a5bb-279c2714af12}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{96ad72e4-2e2b-4ffc-a5bb-279c2714af12}HKEY_CLASSES_ROOT\IEocxApp.IEocxHKEY_CLASSES_ROOT\IEocxApp.IEocx.1HKEY_CLASSES_ROOT\Interface\{4B66E1DF-4DE3-4CDA-83B5-11673EADAB0B}HKEY_CLASSES_ROOT\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}HKEY_CLASSES_ROOT\TypeLib\{A54DC52D-7AAD-4D40-A126-337211631EDC}HKEY_CURRENT_USER\Control Panel\don't load "scui.cpl"HKEY_CURRENT_USER\Control Panel\don't load "wscui.cpl"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Content"

Additional Information on Winpcantivirus2010.com

  • The following domains were detected:
    # Domain
    1 winpcantivirus2010.com
    2 winpc-antivirus09.com
    3 winpc-antivirus.com
    4 winpc-antivirus2009.com
    5 win-pc-antivirus2009.com
    6 winpcantivirus2010.com
    7 winpc-antivirus09.com
    8 winpc-antivirus.com
    9 winpc-antivirus2009.com
    10 win-pc-antivirus2009.com
Loading...