Home Malware Programs Browser Hijackers Winshield2009.com

Winshield2009.com

Posted: September 23, 2009

Winshield2009.com is a malicious website and browser hijacker. Winshield2009.com has the capability of changing settings on your web browser application in addition to displaying misleading notifications leading to the installation of the rogue application Antivirus System PRO. Winshield2009.com is usually followed by a fake system scan that displays bogus results to further mislead computer users into downloading and installing fake security software.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %WINDOWS%\sysguard.exe
    2 %WINDOWS%\system32\iehelper.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AvScanHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "system tool"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}
Loading...