Home Rogue Websites WwwMobileReads.com

WwwMobileReads.com

Posted: April 7, 2009

WwwMobileReads.com is a malicious domain hosting the rogue anti-spyware program System Security 2009. Wwwmobilereads.com is hit after your computer is compromised by the affiliated Trojan Zlob, which infiltrates your system via backdoor techniques and vulnerabilities in your security software. Here is where the Trojan alters your browser settings, and as a result, your web-surfing activities will become interrupted and you will be diverted to the Wwwmobilereads.com web page whether you like it or not.

The website itself is titled "My Computer Online Scan" and actually resembles "My Computer" interface, with all the hard drives, folders and system tasks displayed. The scan that Wwwmobilereads.com performs is a fake, however, and always reports that your PC is infected with numerous parasites, despite this being untrue. You are then persuaded to purchase and install System Security 2009 in order to repair and protect your computer, though System Security 2009 does neither of these and is nothing but a money-stealing scheme.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %\Documents and Settings%\All Users\Application Data\00308937\00308937.exe
    2 %\Documents and Settings%\All Users\Application Data\00308937\config.udb
    3 %\Documents and Settings%\All Users\Application Data\00308937\pc00308937ins
    4 %UserProfile%\Desktop\System Security 2009.lnk
    5 %UserProfile%\Start Menu\Programs\System Security\System Security 2009 Support.lnk
    6 %UserProfile%\Start Menu\Programs\System Security\System Security 2009.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\Software\00308937HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run g00308937HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}SystemSecurity2009
Loading...