Threat Database Browser Hijackers Buy-security-essentials.com

Buy-security-essentials.com

Buy-security-essentials.com is a fraudulent website that is inserted into victims' browsers by browser hijacking Trojans. Once a victim is redirected to Buy-security-essentials.com, a fake system scan will be run claiming that the computer is severely infected with dangerous malware. The victim will then be advised to purchase Security Essentials 2010 in order to rid his/her PC of all the purportedly detected threats. Do not waste your money on the useless Security Essentials 2010 rogueware. Instead, use a legitimate computer security tool to remove Buy-security-essentials.com and all malware related to it.

File System Details

Buy-security-essentials.com may create the following file(s):
# File Name Detections
1. %Temp%\[randomnumbers].exe
2. %System%\winlogon32.exe
3. %Program Files%\Securityessentials2010\SE2010.exe
4. %System%\smss32.exe
5. %Documents and Settings%\[UserName]\Application Data\[randomnumbers].exe
6. %Temp%\[randomnumbers].dll
7. %Program Files%\Securityessentials2010\
8. %Documents and Settings%\[UserName]\Start Menu\Security essentials 2010.lnk
9. %Documents and Settings%\[UserName]\Desktop\Security essentials 2010.lnk

Registry Details

Buy-security-essentials.com may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop

Trending

Most Viewed

Loading...