Home Rogue Websites Malwarescanner20.com

Malwarescanner20.com

Posted: April 13, 2009

Malwarescanner20.com is a malicious website that promotes and persuades the user to install Spyware Guard 2008 which is a rogue anti-spyware program. Malwarescanner20.com fabricates system scans for infections. All of the results displayed on Malwarescanner20.com are bogus. Malwarescanner20.com can prove to be very annoying due to the numerous displays of fake system alerts pop ups. Spyware Guard 2008 and Malwarescanner20.com could be from the same group of attackers and both should be avoided in all situations.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and settings%\user\Application Data\Microsoft\Internet Explorer\olesys.dll
    2 %Documents and settings%\user\Desktop\Spyware Guard 2008.lnk
    3 %Documents and settings%\user\Start Menu\Programs\Spyware Guard 2008\Spyware Guard 2008.lnk
    4 %Documents and settings%\user\Start Menu\Programs\Spyware Guard 2008\Uninstall.lnk
    5 %ProgramFiles%\Spyware Guard 2008\conf.cfg
    6 %ProgramFiles%\Spyware Guard 2008\mbase.vdb
    7 %ProgramFiles%\Spyware Guard 2008\quarantine.vdb
    8 %ProgramFiles%\Spyware Guard 2008\queue.vdb
    9 %ProgramFiles%\Spyware Guard 2008\spywareguard.exe
    10 %ProgramFiles%\Spyware Guard 2008\uninstall.exe
    11 %ProgramFiles%\Spyware Guard 2008\vbase.vdb
    12 %Windows%\reged.exe
    13 %Windows%\spoolsystem.exe
    14 %Windows%\sys.com
    15 %Windows%\syscert.exe
    16 %Windows%\sysexplorer.exe
    17 %Windows%\vmreg.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"spywareguard" = "C:\Program Files\Spyware Guard 2008\spywareguard.exe"HKEY_CURRENT_USER\Software\Spyware GuardHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Spyware Guard 2008
Loading...