Drameset.com
Drameset.com is a malicious browser hijacker which appears to be a legitimate website promoting the rogue anti-spyware program GuardWWW. Drameset.com will produce fake sytem scan results claiming the system is infected with malware. Then it will bombard the user with annoying popups urging the purchase of GuardWWW, which is in fact a defunct product. Do not become another victim of cyber fraud and have these threats removed from the system immediately using a reliable anti-spyware product.
File System Modifications
- The following files were created in the system:
# File Name 1 %Documents and Settings%\All Users\Desktop\GuardWWW.lnk 2 %Documents and Settings%\All Users\Start Menu\Programs\GuardWWW 3 %Documents and Settings%\All Users\Start Menu\Programs\GuardWWW\1 GuardWWW.lnk 4 %Documents and Settings%\All Users\Start Menu\Programs\GuardWWW\2 Homepage.lnk 5 %Documents and Settings%\All Users\Start Menu\Programs\GuardWWW\3 Uninstall.lnk 6 %Program Files%\GuardWWW Software 7 %Program Files%\GuardWWW Software\GuardWWW 8 %Program Files%\GuardWWW Software\GuardWWW\GuardWWW.exe 9 %Program Files%\GuardWWW Software\GuardWWW\main_config.xml 10 %Program Files%\GuardWWW Software\GuardWWW\uninstall.exe 11 %Temp%\[random].exe 12 %WINDOWS%\system32\[random].exe
Registry Modifications
- The following newly produced Registry Values are:
HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\GuardWWWHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random].exe"HKEY_LOCAL_MACHINE\SOFTWARE\GuardWWWHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "GuardWWW"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}GuardWWW
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.