Staeshine.com

Staeshine.com is a malicious website that promotes the fake security application called Virus Protector. Staeshine.com may enter users' browsers via fake online scanners or Trojan programs. Once a victim is redirected to Staeshine.com, the size of the browser window will reduce and alarming security pop-ups will be displayed claiming that the system is infected with malware. Clicking on the pop-ups will trigger a fake online system scan that resembles the My Computer Windows GUI. The scan report will indicate that the system is infected with malware such as viruses, Trojans, worms etc and the only solution is to purchase the "full" version of Virus Protector. This is all a malicious scam. If you encounter Staeshine.com have your system scanned for browser hijackers and any other malware associated with the malignant domain.

File System Details

Staeshine.com may create the following file(s):
# File Name Detections
1. %Documents and Settings%\[UserName]\Local Settings\Temp\[random].exe
2. %Program Files%\Internet Explorer\[random].dll
3. %WINDOWS%\system32\[random].exe
4. %WINDOWS%\system32\drivers\[random].dll
5. %Documents and Settings%\[UserName]\Application Data\[random].dll
6. %Program Files%\Internet Explorer\[random].exe
7. %WINDOWS%\[random].dll
8. %WINDOWS%\system32\drivers\[random].exe
9. %Documents and Settings%\[UserName]\Application Data\[random].exe
10. %Documents and Settings%\[UserName]\Local Settings\Temp\[random].dll
11. %WINDOWS%\[random].exe
12. %WINDOWS%\system32\[random].dll

Registry Details

Staeshine.com may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows "AppInit_DLLs" = "[random].dll"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows "LoadAppInit_DLLs" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Virus Protector"

Trending

Most Viewed

Loading...