Home Malware Programs Browser Hijackers Av-guru.microsoft.com

Av-guru.microsoft.com

Posted: March 8, 2010

Av-guru.microsoft.com is a browser hijacker which redirects Internet users to a corrupt site which distributes Antivirus Soft rogueware. Av-guru.microsoft.com uses malicious Trojans to provide entry to the system. Once active, Av-guru.microsoft.com changes the browser settings and starts promoting Antivirus Soft by running a fake system scan. The scan will produce bogus results claiming the PC is infected with all sorts of malware. Do not fall for this, it's blatant lie. Next the user will be bombarded by popups urging the purchase of Antivirus Soft to remove the alleged threats. Do not become another hapless victim of a cyber scam. Remove Av-guru.microsoft.com and the Trojans related using reliable antivirus software.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]sysguard.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AvScanHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5555"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random string]"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random string]"
Loading...