Home Malware Programs Browser Hijackers Yourbrowserprotection.com

Yourbrowserprotection.com

Posted: September 30, 2009

Yourbrowserprotection.com is a browser hijacker that advertises fake security applications mainly the Total Security rogue anti-spyware program. Yourbrowserprotection.com can hijack a computers web browser program changing settings and redirecting computer users to other malicious sites. System notification messages displayed by Yourbrowserprotection.com are bogus and cannot be trusted.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Program Files%\TSC\Sc2C21UvvM.exe
    2 %Program Files%\TSC\tsc.exe
    3 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\TSC.lnk
    4 %UserProfile%\Desktop\TSC.lnk
    5 %UserProfile%\Start Menu\TSC\Help.lnk
    6 %UserProfile%\Start Menu\TSC\Registration.lnk
    7 %UserProfile%\Start Menu\TSC\TSC.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\1FD92E3F7C34799BFB075C41DA05D1FEHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "1FD92E3F7C34799BFB075C41DA05D1FE"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = "1?HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = "1?HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D263FA6D-84CC-48A8-9AF6-C664362B7A5B}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{D263FA6D-84CC-48A8-9AF6-C664362B7A5B}
Loading...