Av-guru.net

Av-guru.net is a malicious website that users who are infected with Antivirus Soft are usually redirected to. The same Trojan that installs Antivirus Soft into a compromised PC also inserts Av-guru.net into the browser causing a victim to be constantly redirected to the misleading domain. Av-guru.net displays a fake computer security warning and recommends that the victim purchase the "full" version of Antivirus Soft in order to remove all the detected computer threats. Do not believe anything on Av-guru.net; the fake malware detections are all part of a scam to obtain unsuspecting users' money.

File System Details

Av-guru.net may create the following file(s):
# File Name Detections
1. sysguard.exe
2. %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]

Registry Details

Av-guru.net may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random string]"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1?
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random string]"
HKEY_CURRENT_USER\Software\AvScan
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5555?

Trending

Most Viewed

Loading...