I-Worm.Trojan.b

I-Worm.Trojan.b is a fake infection displayed on a Windows Security Center pop-up, exploited by the rogue anti-spyware application called System Security 2009 in order to get people to purchase this malicious software. Typically, the pop-up is displayed on a webpage you are redirected to due to a hijacker modifying your browser settings, causing unwanted diverts to malicious domains. It is on such insecure websites that you may receive this misleading alert message, which reads:

"Windows Security Center - Virus (I-Worm.Trojan.b) was found on your computer! Click OK to install System Security Antivirus."

You are then prompted to download and install System Security 2009, which will be executed and run each and every time your computer starts up. This will lead to further fake notifications flooding your system, along with fraudulent infection reports, all in order to scare you into purchasing and installing the full version of System Security 2009.

File System Details

I-Worm.Trojan.b may create the following file(s):
# File Name Detections
1. %\Documents and Settings%\All Users\Application Data\00308937\00308937.exe
2. %UserProfile%\Desktop\System Security 2009.lnk
3. %\Documents and Settings%\All Users\Application Data\00308937\config.udb
4. %UserProfile%\Start Menu\Programs\System Security\System Security 2009.lnk
5. %\Documents and Settings%\All Users\Application Data\00308937\pc00308937ins
6. %UserProfile%\Start Menu\Programs\System Security\System Security 2009 Support.lnk

Registry Details

I-Worm.Trojan.b may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SystemSecurity2009
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "00308937"
HKEY_LOCAL_MACHINE\Software\00308937

Related Posts

Trending

Most Viewed

Loading...