Home Malware Programs Fake Warning Messages CoreGuard Safebrowser

CoreGuard Safebrowser

Posted: May 6, 2009

CoreGuard Safebrowser (or SafeExplorer) pop-up is the latest error message related to the CoreGuard Antivirus 2009 (CoreGuardAntivirus2009) infection. CoreGuard Safebrowser pop-up message resembles the recent dangerous CoreGuard Antivirus 2009 message, which incessantly frustrates you with the non-stop alerts. The CoreGuard Antivirus 2009 infection that displays the CoreGuard Safebrowser pop-up is known to install Trojans such as Zlob, Generic and even Vundo. It is highly recommended that you do not click on any suspicious messages or links that may appear on your computer, as they may be connected to CoreGuard Safebrowser pop-up.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Coreguard 2009.lnk
    2 %UserProfile%\Desktop\Coreguard 2009.lnk
    3 %UserProfile%\Start Menu\Programs\Coreguard Antivirus 2009
    4 %UserProfile%\Start Menu\Programs\Coreguard Antivirus 2009\Coreguard 2009.lnk
    5 %UserProfile%\Start Menu\Programs\Coreguard Antivirus 2009\Uninstall Coreguard Antivirus 2009.lnk
    6 c:\Program Files\Coreguard Antivirus 2009
    7 c:\Program Files\Coreguard Antivirus 2009\blacklist.cga
    8 c:\Program Files\Coreguard Antivirus 2009\core.cga
    9 c:\Program Files\Coreguard Antivirus 2009\CoreExt.dll
    10 c:\Program Files\Coreguard Antivirus 2009\Coreguard 2009.exe
    11 c:\Program Files\Coreguard Antivirus 2009\firewall.dll
    12 c:\Program Files\Coreguard Antivirus 2009\Help
    13 c:\Program Files\Coreguard Antivirus 2009\Help\images
    14 c:\Program Files\Coreguard Antivirus 2009\Help\images\buttons
    15 c:\Program Files\Coreguard Antivirus 2009\Help\images\buttons\offline.gif
    16 c:\Program Files\Coreguard Antivirus 2009\Help\images\buttons\online.gif
    17 c:\Program Files\Coreguard Antivirus 2009\Help\images\buttons\voice.gif
    18 c:\Program Files\Coreguard Antivirus 2009\Help\images\delete.png
    19 c:\Program Files\Coreguard Antivirus 2009\Help\images\info.png
    20 c:\Program Files\Coreguard Antivirus 2009\Help\images\plus_circle.png
    21 c:\Program Files\Coreguard Antivirus 2009\Help\images\tick.png
    22 c:\Program Files\Coreguard Antivirus 2009\Help\images\warn.png
    23 c:\Program Files\Coreguard Antivirus 2009\Help\reg.html
    24 c:\Program Files\Coreguard Antivirus 2009\Help\support.png
    25 c:\Program Files\Coreguard Antivirus 2009\Help\unreg.html
    26 c:\Program Files\Coreguard Antivirus 2009\Uninstall.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\CoreGuardHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Coreguard Antivirus 2009"HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Coreguard Antivirus 2009
Loading...