Home Rogue Websites ProtectGuru.com

ProtectGuru.com

Posted: March 29, 2010

ProtectGuru.com is a malicious site which is created by malicious hackers behind the Antivirus Soft cyber-scam. ProtectGuru.com produces fake pop-ups and uses a browser hijacker to redirect users to this malicious site everytime the Internet is accessed. ProtectGuru.com uses Trojans to promote Antivirus Soft by running a fake scan which claims the system is infected. The bogus warnings will urge you to purchase Antivirus Soft. Do not fall for this blatant scam and have protectGuru.com removed using a reliable anti-spyware program.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Local Settings\Application Data\[RANDOM]
    2 %UserProfile%\Local Settings\Application Data\[RANDOM]\[RANDOM]ftav.exe
    3 %UserProfile%\Local Settings\Application Data\[RANDOM]\[RANDOM]sysguard.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AvScanHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\[RANDOM]HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\[RANDOM
Loading...