Home Malware Programs Browser Hijackers AV-Crew.net

AV-Crew.net

Posted: March 2, 2010

AV-Crew.net is another online trap for the rogue anti-virus program Antivirus Soft. The AV-Crew.net browser hijacker uses malicious Trojans to modify the browser settings and corrupt the Hosts file. After this you will continuously be redirected to AV-Crew.net which produces a fake system scan page and false results. These fake warnings will try and convince you that your PC is infected with a multitude of malware. AV-Crew.net will then redirect you to a site that distributes a paid commercial version of Antivirus Soft. Remove the AV-Crew.net hijacker and all Antivirus Soft's threats with reliable anti-virus software.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random]sftav.exe
    2 %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random]sysguard.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AvScanHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5555"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random]"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random]"
Loading...