Home Rogue Websites Antick.Info

Antick.Info

Posted: August 11, 2009

Antick.Info is a rogue website sponsoring the distribution of the fake spyware remover Internet Antivirus Pro. To achieve this goal, trojans infiltrate your computer by way of security vulnerabilities and alter the browser settings, causing web-surfing activities to be interrupted and diverted to the Antick.Info web page. Once here, your PC is subject to a fake online scan that depicts fabricated infection results in order to scare you into purchasing the rogue spyware remover Internet Antivirus Pro.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %APPDATA%\Microsoft\Windows\winlogon.exe
    2 %LOCAL APPDATA%\Microsoft\Internet Explorer\iv.exe
    3 %LOCAL APPDATA%\Microsoft\Windows\services.exe
    4 %Program Files%\Internet Antivirus Pro\iapro.exe
    5 iainstall.exe
    6 iapro.exe
    7 install.exe
    8 InternetAntivirusPro.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Internet Antivirus ProHKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Policies\Explorer\run "iv":HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Run "Internet Antivirus Pro"HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Runonce "3p_udec_ia"
Loading...