Drlcleaner.info

Drlcleaner.info is a malicious website and hijacker that is responsible for distributing and promoting the rogue anti-spyware program Safety Center. Drlcleaner.info uses many deceiving words to describe to computer users how they need to purchase Safety Center to remove spyware threats. Drlcleaner.info can install a Trojan that is capable of download malware onto the infected system without any interaction required by the computer user.

File System Details

Drlcleaner.info may create the following file(s):
# File Name Detections
1. %UserProfile%\My Documents\cs_def.exe
2. %UserProfile%\My Documents\install_tag002.exe
3. %UserProfile%\My Documents\102.exe
4. %UserProfile%\My Documents\Adrevolver.txtAds360.com
5. %Program Files%\SafetyCenter\protector.exe
6. %UserProfile%\My Documents\trojan.psw.stealth.a.exe
7. %UserProfile%\My Documents\tdfhex.dll
8. %UserProfile%\My Documents\0886b8.vom
9. %WINDOWS%\gbaxl2.dat
10. %Program Files%\SafetyCenter\sound.wav
11. %UserProfile%\My Documents\emalware.cvd
12. %Program Files%\SafetyCenter\main.ico
13. %UserProfile%\My Documents\default.pss

Registry Details

Drlcleaner.info may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EB09B56A-91AB-11DE-95FD-A39056D89593}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\{BCA9B86C-91BC-11DE-B1CD-35C755D89593}
HKEY_LOCAL_MACHINE\SOFTWARE\SafetyCenter
HKEY_CLASSES_ROOT\CLSID\{EB09B56A-91AB-11DE-95FD-A39056D89593}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{BCA9B86C-91BC-11DE-B1CD-35C755D89593}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SafetyCenter
HKEY_CLASSES_ROOT\CLSID\{BCA9B86C-91BC-11DE-B1CD-35C755D89593}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{BCA9B86C-91BC-11DE-B1CD-35C755D89593}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\NetworkNeighborhood\NameSpace\{BCA9B86C-91BC-11DE-B1CD-35C755D89593}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce "SafetyCenter"

Trending

Most Viewed

Loading...