Home Malware Programs Browser Hijackers Av-guru.net

Av-guru.net

Posted: March 8, 2010

Av-guru.net is a corrupt website and browser hijacker which distributes Antivirus Soft rogueware. Av-guru.net uses affiliated Trojans to install everything stealthily. Once active, Av-guru.net changes the browser settings and starts promoting Antivirus Soft by running a fake system scan. The scan will produce bogus results claiming the PC is infected with all sorts of malware. Do not fall for this, it's a blatant lie. Next the user will be bombarded by popups urging the purchase of Antivirus Soft to remove the alleged threats. Do not become another hapless victim of a cyber scam. Remove Av-guru.net using a reliable malware remover.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]
    2 sysguard.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AvScanHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1?HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5555?HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random string]"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random string]"
Loading...