Home Malware Programs Browser Hijackers Windows-shield.com

Windows-shield.com

Posted: September 21, 2009

Windows-shield.com is a malicious browser hijacker that distributes and advertises the Antivirus System PRO rogue anti-spyware program. Windows-shield.com uses misleading descriptions to push computer users into downloading and purchasing the full Antivirus System PRO application. Windows-shield.com can change browser settings. Windows-shield.com may appear to come from a Microsoft.com domain listed as Windows-shield.microsoft.com. Computer users must know that Windows-shield.com is not connected or associated with Microsoft in anyway way.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %WINDOWS%\sysguard.exe
    2 %WINDOWS%\system32\iehelper.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AvScanHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "system tool"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}
Loading...