Mar 08

Threat Description:

Salebogs.com is all about making a PC user think he/she has got tons of security problems. This site is by all means hazardous as it contains rogueware downloader and is full of trojans. Virus Protector is the program being promoted by Salebogs.com; the online scan that runs there ends in recommending a victim to download and execute an allegedly helpful antivirus tool. Internet traffic is being driven to Salebogs.com through blackhat SEO, which means hackers try to trick people into clicking some attractive ad or open up some attachment to an Email letter from an unknown insecure source. Either way, one hits Salebogs.com unknowingly and probably not wanting to. You can check out what Salebogs.com is like by taking a quick look at the screenshot we made of it. It’s obvious that Salebogs.com tries to trade off its similarity with My computer interface of Windows OS. That look-alike page is not what it seems though. Salebogs.com is a pre-designed HTML script which is programmed to always display the same animation. So it doesn’t perform any sort of virus check for real. Salebogs.com exists for only one basic purpose – to make credulous computer users let Virus Protector rogue anti-spyware inside. Of course, Virus Protector will keep on ‘detecting’ tons of malware on your PC to make you buy its license, no doubt about that. So to prevent computer invasion, please take some measures to remove Salebogs.com browser hijacker ASAP.

Determine if your system is infected with Salebogs.com hijacker and related threats:

Salebogs.com Screenshot:

Salebotw.com

How to remove this threat manually:

Salebogs.com manual uninstall procedure:

Get rid of the related corrupt files:

  • %Documents and Settings%\[UserName]\Application Data\[random].exe
  • %Documents and Settings%\[UserName]\Application Data\[random].dll
  • %Documents and Settings%\[UserName]\Local Settings\Temp\[random].exe
  • %Documents and Settings%\[UserName]\Local Settings\Temp\[random].dll
  • %Program Files%\Internet Explorer\[random].exe
  • %Program Files%\Internet Explorer\[random].dll
  • %WINDOWS%\[random].exe
  • %WINDOWS%\[random].dll
  • %WINDOWS%\system32\[random].exe
  • %WINDOWS%\system32\[random].dll
  • %WINDOWS%\system32\drivers\[random].exe
  • %WINDOWS%\system32\drivers\[random].dll

Delete the associated registry entries:

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Virus Protector”
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows “LoadAppInit_DLLs” = “1″
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows “AppInit_DLLs” = “[random].dll”

Please note that Salebogs.com manual removal is a procedure of high complexity and should be performed with extreme caution. Lack of the required skills and even the slightest deviation from the instructions may cause irreparable system damage. To ensure trouble-free deletion, it is recommended to use the automatic removal tool below:

Download Salebogs.com Hijacker Removal Tool

Leave a Reply