Home Rogue Websites virusalarm-scanvirus.com

virusalarm-scanvirus.com

Posted: April 17, 2009

Virusalarm-scanvirus.com is a dangerous and malicious website that advertises and spread the Virus Alarm rogue anti-spyware program. Virusalarm-scanvirus.com is part of the scam of selling the Virus Alarm application through a multiple of fake popup messages and system alerts. Virusalarm-scanvirus.com should never be visited. If you have any programs downloaded from Virusalarm-scanvirus.com, then you should utilize a good spyware detection tool to remove any traces of malware related to Virusalarm-scanvirus.com.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %\Documents and Settings%\All Users\Application Data\7c69f0c
    2 %\Documents and Settings%\All Users\Application Data\7c69f0c\LoopSystem
    3 %\Documents and Settings%\All Users\Application Data\7c69f0c\LoopSystem\vd952342.bd
    4 %\Documents and Settings%\All Users\Application Data\7c69f0c\VSweep.exe
    5 %\Documents and Settings%\All Users\Application Data\LoopSystem
    6 %\Documents and Settings%\All Users\Application Data\LoopSystem\swcfg.ini
    7 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Virus Sweeper.lnk
    8 %UserProfile%\Application Data\Virus Sweeper
    9 %UserProfile%\Application Data\Virus Sweeper\Instructions.ini
    10 %UserProfile%\Desktop\Virus Sweeper.lnk
    11 %UserProfile%\Recent\ANTIGEN.drv
    12 %UserProfile%\Recent\cb.dll
    13 %UserProfile%\Recent\CLSV.dll
    14 %UserProfile%\Recent\energy.exe
    15 %UserProfile%\Recent\exec.dll
    16 %UserProfile%\Recent\fix.sys
    17 %UserProfile%\Recent\PE.exe
    18 %UserProfile%\Recent\PE.sys
    19 %UserProfile%\Recent\ppal.tmp
    20 %UserProfile%\Recent\snl2w.drv
    21 %UserProfile%\Recent\tjd.exe
    22 %UserProfile%\Recent\tjd.tmp
    23 %UserProfile%\Start Menu\Programs\Virus Sweeper.lnk
    24 %UserProfile%\Start Menu\Virus Sweeper.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "97680312703"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Virus Sweeper"HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}HKEY_CLASSES_ROOT\VSweep.DocHostUIHandler
Loading...