Home Rogue Websites Osadwarekill2009.com


Posted: December 4, 2009

Osadwarekill2009.com (aka Osadwarekill2009.microsoft.com) is a cyber threat that represents an entire army of browser hijackers which promote the purchasing of Antivirus System PRO badware. Osadwarekill2009.com hacks your system and injects a web browser in the shape of Osadwarekill2009.microsoft.com. Osadwarekill2009.com acts as a warning page which tells you that you have run into malicious internet activity. Osadwarekill2009.microsoft.com is not related to Microsoft and is a fraudulent attempt to sell Antivirus System PRO. Do not trust anything on Osadwarekill2009.microsoft.com as it will lure you into buying Antivirus System PRO. Don't be fooled, get rid of the Osadwarekill2009.com threat immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %WINDOWS%\sysguard.exe
    2 %WINDOWS%\system32\iehelper.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AvScanHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "system tool"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}