Home Malware Programs Rogue Anti-Virus Programs Antivir 2010

Antivir 2010

Posted: January 29, 2010

Antivir 2010 is a rogue anti-virus program which has proven to be extremely intricate and dangerous to computer systems. The Antivir 2010 application emanates from the same family of rogues as Alpha Antivirus and Antivir. Once Antivir 2010 infects a computer, it displays an icon with a message, which says the computer is infected with spyware and asks the user to download the Antivir 2010 program. Antivir 2010 can also change the desktop settings, hijack the web browser, and display an icon in the system tray. Remove Antivir 2010 before it starts creating chaos on the system.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\All Users\Start Menu\AV
    2 %Documents and Settings%\All Users\Start Menu\AV\Antivir 2010.lnk
    3 %Documents and Settings%\All Users\Start Menu\AV\Uninstall.lnk
    4 %Program Files%\AV
    5 %Program Files%\AV\antivir2010.exe
    6 %Program Files%\Common Files\Uninstall
    7 %Program Files%\Common Files\Uninstall\AV
    8 %Program Files%\Common Files\Uninstall\AV\Uninstall.lnk
    9 %UserProfile%\Desktop\Antivir 2010.lnk
    10 %WINDOWS%\system32\UpdateCheck.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\EVAACDHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "AV"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Antivir 2010

One Comment

Loading...