Home Rogue Websites Awareremover2009.microsoft.com

Awareremover2009.microsoft.com

Posted: November 24, 2009

Awareremover2009.microsoft.com (or Awareremover2009.com) is where the Antivirus System Pro fake anti-spyware is malvertised. Awareremover2009.microsoft.com is an annnoying hijacker which totally deceives PC users. It creeps into the computer system and stealthily modifies the Hosts file before redirecting Internet sessions to a fake alert page. Awareremover2009.microsoft.com is not associated with Microsoft and only uses the name to be more persuasive. The fake warnings generated by Awareremover2009.microsoft.com claims your Internet is being threatened by bizarre hazards. The hijacker will attempt to make the user follow the suggested link and consequently find Awareremover2009.com which seems to be the Antivirus System PRO official website. Do not fall for Awareremover2009.microsoft.com tricks, instead get rid of this browser hijacker and the other trialware which may have infiltrated the system.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %WINDOWS%\sysguard.exe
    2 %WINDOWS%\system32\iehelper.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AvScanHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “system tool”HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}
Loading...