Home Malware Programs Browser Hijackers Drameset.com

Drameset.com

Posted: February 4, 2010

Drameset.com is a malicious browser hijacker which appears to be a legitimate website promoting the rogue anti-spyware program GuardWWW. Drameset.com will produce fake sytem scan results claiming the system is infected with malware. Then it will bombard the user with annoying popups urging the purchase of GuardWWW, which is in fact a defunct product. Do not become another victim of cyber fraud and have these threats removed from the system immediately using a reliable anti-spyware product.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\All Users\Desktop\GuardWWW.lnk
    2 %Documents and Settings%\All Users\Start Menu\Programs\GuardWWW
    3 %Documents and Settings%\All Users\Start Menu\Programs\GuardWWW\1 GuardWWW.lnk
    4 %Documents and Settings%\All Users\Start Menu\Programs\GuardWWW\2 Homepage.lnk
    5 %Documents and Settings%\All Users\Start Menu\Programs\GuardWWW\3 Uninstall.lnk
    6 %Program Files%\GuardWWW Software
    7 %Program Files%\GuardWWW Software\GuardWWW
    8 %Program Files%\GuardWWW Software\GuardWWW\GuardWWW.exe
    9 %Program Files%\GuardWWW Software\GuardWWW\main_config.xml
    10 %Program Files%\GuardWWW Software\GuardWWW\uninstall.exe
    11 %Temp%\[random].exe
    12 %WINDOWS%\system32\[random].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\GuardWWWHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random].exe"HKEY_LOCAL_MACHINE\SOFTWARE\GuardWWWHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "GuardWWW"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}GuardWWW
Loading...