Home Malware Programs Fake Warning Messages Coreguard SafeExplorer

Coreguard SafeExplorer

Posted: May 7, 2009

Coreguard SafeExplorer is the same type of error message as CoreGuard Safebrowser, which comes from the rogue anti-spyware application CoreGuard Antivirus 2009 (CoreGuardAntivirus2009). Coreguard SafeExplorer may read similar to the CoreGuard Antivirus 2009 warning message. If your system has CoreGuard Antivirus 2009 installed, then you may repeatedly get the Coreguard SafeExplorer message. Coreguard SafeExplorer must not be clicked on or it could result in the installation of malware onto your system. The Coreguard SafeExplorer is part of the same scheme that CoreGuard Antivirus 2009 attempts to carry-out. It is important to detect and remove all traces of the Coreguard SafeExplorer message including the Coreguard Antivirus 2009 application to prevent damage to your system.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Coreguard 2009.lnk
    2 %UserProfile%\Desktop\Coreguard 2009.lnk
    3 %UserProfile%\Start Menu\Programs\Coreguard Antivirus 2009\Coreguard 2009.lnk
    4 %UserProfile%\Start Menu\Programs\Coreguard Antivirus 2009\Uninstall Coreguard Antivirus 2009.lnk
    5 c:\Program Files\Coreguard Antivirus 2009\blacklist.cga
    6 c:\Program Files\Coreguard Antivirus 2009\core.cga
    7 c:\Program Files\Coreguard Antivirus 2009\Help\images\buttons\offline.gif
    8 c:\Program Files\Coreguard Antivirus 2009\Help\images\buttons\online.gif
    9 c:\Program Files\Coreguard Antivirus 2009\Help\images\buttons\voice.gif
    10 c:\Program Files\Coreguard Antivirus 2009\Help\images\delete.png
    11 c:\Program Files\Coreguard Antivirus 2009\Help\images\info.png
    12 c:\Program Files\Coreguard Antivirus 2009\Help\images\plus_circle.png
    13 c:\Program Files\Coreguard Antivirus 2009\Help\images\tick.png
    14 c:\Program Files\Coreguard Antivirus 2009\Help\images\warn.png
    15 c:\Program Files\Coreguard Antivirus 2009\Help\reg.html
    16 c:\Program Files\Coreguard Antivirus 2009\Help\support.png
    17 c:\Program Files\Coreguard Antivirus 2009\Help\unreg.html

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\CoreGuardHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Coreguard Antivirus 2009"HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Coreguard Antivirus 2009
Loading...