Mar 03

Threat Description:

The people who designed Avgroupwebsite.com want to take your money and run off. Actually, Avgroupwebsite.com is live to promote the program called Antivirus Soft. Please allow us just a little digression – Antivirus Soft is rogue anti-malware utility being rotated to arrive at one basic goal. It scares people into buying this scam software, Avgroupwebsite.com being a domain helping this rogueware achieve this had objective. Antivirus Soft tends to change your browser configuration and reset the HOSTS file to fit your Internet surfing into browser redirect loop. So you will have some hard time attempting to access a random site. Avgroupwebsite.com will show in browser location bar instead of pretty much every URL you are targeting. There exist two variants of this hijacker. One looks like Internet Explorer warning that notifies you about unsafe online activity. The other is Antivirus Soft official site (see screenshot). Both are misleading and must not be taken for granted unless you don’t mind purchasing dangerous rogue anti-spyware. Anyway, you should keep away from Avgroupwebsite.com. In case you cannot control browser redirects to Avgroupwebsite.com, be sure to take care of some trojans that make this unwanted thing happen.

Determine if your system is infected with Avgroupwebsite.com hijacker and related threats:

Avgroupwebsite.com Screenshot:

Avgroupwebsite.com

How to remove this threat manually:

Avgroupwebsite.com manual uninstall procedure:

Get rid of the related corrupt files:

  • %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]sysguard.exe
  • %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]sftav.exe

Delete the associated registry entries:

  • HKEY_CURRENT_USER\Software\AvScan
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “RunInvalidSignatures” = “1″
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyOverride” = “”
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyServer” = “http=127.0.0.1:5555″
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random string]“
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “[random string]“

Please note that Avgroupwebsite.com manual removal is a procedure of high complexity and should be performed with extreme caution. Lack of the required skills and even the slightest deviation from the instructions may cause irreparable system damage. To ensure trouble-free deletion, it is recommended to use the automatic removal tool below:

Download Avgroupwebsite.com Removal Tool

Leave a Reply