Home Malware Programs Browser Hijackers Av-armor.com

Av-armor.com

Posted: April 8, 2010

Av-armor.com is a browser hijacker that promotes Antivirus Suite. Internet users infected with malware related to this scam will continuously be redirected to Av-armor.com which appears to be a system scan webpage. Av-armor.com will run the scan which produces bogus results claiming the system is infected. Users will then be bombarded by popup warnings which claim only Antivirus Suite can remove the alleged threats. Antivirus Suite is useless and the only threats on your PC are those related to this blatant scam.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]ftav.exe
    2 %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]sysguard.exe
    3 %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]tssd.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = "no"HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5555"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = ".exe"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"[random string].exe"HKEY_LOCAL_MACHINE\SOFTWARE\avsuiteHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"[random string].exe"
Loading...