Home Rogue Websites 2dayoftheweek.com

2dayoftheweek.com

Posted: August 30, 2011

If you constantly get redirected to 2dayoftheweek.com when searching for terms on Google, then your PC is infected with the ZeroAccess rootkit. Malware threats associated with 2dayoftheweek.com may slow down the computer, change system files and forward personal information to remote attackers. Malware threats will also bombard you with annoying pop-up ads and redirect your web browser to malicious websites similar to 2dayoftheweek.com. Malware like ZeroAccess will also block you from using security programs. You should find a reputable anti-spyware application to remove ZeroAccess and set your browser settings to avoid redirections to 2dayoftheweek.com.

Technical Details

File System Modifications

The following files were created in the system:



C:\WINDOWS\system32\drivers\UAC.sys File name: C:\WINDOWS\system32\drivers\UAC.sys
File type: System file
Mime Type: unknown/sys
C:\WINDOWS\Temp\_VOIDtmp File name: C:\WINDOWS\Temp\_VOIDtmp
C:\WINDOWS\Temp\UAC.tmp File name: C:\WINDOWS\Temp\UAC.tmp
File type: Temporary File
Mime Type: unknown/tmp
%Temp%\UAC.tmp File name: %Temp%\UAC.tmp
File type: Temporary File
Mime Type: unknown/tmp
%Temp%\_VOID.tmp File name: %Temp%\_VOID.tmp
File type: Temporary File
Mime Type: unknown/tmp
C:\WINDOWS\system32\drivers\_VOID.sys File name: C:\WINDOWS\system32\drivers\_VOID.sys
File type: System file
Mime Type: unknown/sys

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce.exe
Loading...