Home Malware Programs Browser Hijackers Homepageroze.com

Homepageroze.com

Posted: October 20, 2008

Homepageroze.com is a browser hijacker designed to distribute rogue anti-spyware programs Windows Antivirus 2008 and Ultimate Antivirus 2008. Once your computer is infected with Homepageroze.com, you'll be redirected to homepageroze.com/security/xp/ or homepageroze.com/security/vista/ to purchase rogue anti-spyware programs under the assumption they're legitimate programs. As soon as you are redirected to any of these malicious websites, you'll receive fake popups messages offering Ultimate Antivirus 2008 or Windows Antivirus 2008 programs for your computer's safety. Homepageroze.com's fake popup may read:
The page at Homepageroze.com says:

"Warning!
W32.Myzor.FK@yf is a virus that infects files with .exe extensions. It attempts to steal passwords and private information from the infected computer.

Type: Virus
Infection Length: 138,293 bytes
Systems Affected: Windows 95, 98, ME, NT (all versions), 2003, Windows XP (all service packs)

Systems Not Affected: DOS, EPOC, Linux, Macintosh, Novell Netware, OS/2, UNIX
Technical details: 1. Creates files in %Windir%\ directory. By default, this is C:\Windows.

2. Adds values to registry keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

3. Scans the hard drive for .exe files and infects any executable files.
Searches for passwords/information, which it may send to a remote attacker.

Recomendations: Click "OK" to download officially approved security software.
Always keep your patch levels up-to-date."

You may have Homepageroze.com as your default homepage because you've unknowningly downloaded malware, which can change your system's settings, or you've clicked on a link from a spam email or fake pop-up message.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 cfqbw.dll
    2 fdpzgi.dll
    3 gtawclv.dll
    4 iesplugin.dll
    5 isaddon.dll
    6 khtbpdl.dll
    7 Online Security Guide.url
    8 Security Troubleshooting.url
    9 veptlh.dll
    10 vjxwnn.dll
    11 vmlwp.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70d17a5f-ef27-4295-90f5-20ad6f24834f}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{80ced3d6-ece9-48ba-8df8-2503d8d87c2b}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D61D7E1A-6613-49CA-B6F9-51DB248E209D}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{aa6d4f53-4c8d-4549-84d2-02d584acc4e9}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper objects\{D61D7E1A-6613-49CA-B6F9-51DB248E209D}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}IExplorer Security Plug-inaInternet Explorer Secure BarMessenger Service
Loading...