Home Rogue Websites Antivguardian.com

Antivguardian.com

Posted: May 8, 2009

Antivguardian.com is a rogue website that is home to the fake spyware remover called Spyware Protect 2009. The most common way to hit Antivguardian.com domain is through being redirected there from a misleading web page at Browser-security.microsoft.com which contains a link to push if you want to keep your computer secure. Once you follow the misleadingly suggested reference, you will be taken to Antivguardian.com domain which contains adware pushing Spyware Protect 2009 fraud. Another way of being diverted to the Antivguardian.com webpage is through affiliated trojan viruses infiltrating your system and altering browser settings. The only purpose Antivguardian.com appears to serve is the shameless pimping of its product, Spyware Protect 2009.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %WINDOWS%\aazalirt.exe
    2 %WINDOWS%\dkekkrkska.exe
    3 %WINDOWS%\dkewiizkjdks.exe
    4 %WINDOWS%\iddqdops.exe
    5 %WINDOWS%\ienotas.exe
    6 %WINDOWS%\iqmcnoeqz.exe
    7 %WINDOWS%\irprokwks.exe
    8 %WINDOWS%\jikglond.exe
    9 %WINDOWS%\jiklagka.exe
    10 %WINDOWS%\jrjakdsd.exe
    11 %WINDOWS%\jungertab.exe
    12 %WINDOWS%\kitiiwhaas.exe
    13 %WINDOWS%\kkwknrbsggeg.exe
    14 %WINDOWS%\klopnidret.exe
    15 %WINDOWS%\krkdkdkee.exe
    16 %WINDOWS%\krkmahejdk.exe
    17 %WINDOWS%\krtawefg.exe
    18 %WINDOWS%\krujmmwlrra.exe
    19 %WINDOWS%\ktknamwerr.exe
    20 %WINDOWS%\kuruhccdsdd.exe
    21 %WINDOWS%\ooorjaas.exe
    22 %WINDOWS%\oranerkka.exe
    23 %WINDOWS%\oropbbsee.exe
    24 %WINDOWS%\otnnbektre.exe
    25 %WINDOWS%\otowjdseww.exe
    26 %WINDOWS%\otpeppggq.exe
    27 %WINDOWS%\rkaskssd.exe
    28 %WINDOWS%\ronitfst.exe
    29 %WINDOWS%\seeukluba.exe
    30 %WINDOWS%\skaaanret.exe
    31 %WINDOWS%\sysguardn.exe
    32 %WINDOWS%\tobmygers.exe
    33 %WINDOWS%\tobykke.exe
    34 %WINDOWS%\zibaglertz.exe
    35 Spyware Protect 2009.lnk
    36 Uninstall Spyware Protect 2009.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AvScanHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "sysguardn"
Loading...