Home Rogue Websites OS-guard.com

OS-guard.com

Posted: October 5, 2009

OS-guard.microsoft.com or also known as OS-guard.com, is a malicious web site that is designed to promote and sell the rogue anti-spyware application Antivirus System PRO. OS-guard.microsoft.com is not related to Microsoft despite the domain name. OS-guard.microsoft.com can infect a computer and instruct it to redirect the web browser to the IP 91.212.127.226. Through the OS-guard.microsoft.com website it will alert computer users of fake threats in an effort to make them believe they must purchase Antivirus System PRO to resolve the issue.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %WINDOWS%\sysguard.exe
    2 %WINDOWS%\system32\iehelper.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AvScanHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "system tool"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}
Loading...