Home Malware Programs Rogue Anti-Spyware Programs Antivir System PRO

Antivir System PRO

Posted: May 7, 2009

Antivir System PRO (also referred to as AntivirSystemPRO or AntivirSystem PRO) is a rogue anti-spyware application that descends from a long family line of other well known fake anti-spyware programs, such as System Guard 2009 and Spyware Protect 2009. The unregistered version of Antivir System PRO spreads via browser-hijacking methods or through trojans that utilize security exploits in order to infiltrate your PC. Once active and running, Antivir System PRO displays numerous fake and annoying pop-up windows claiming your computer is infected, or it will report various fabricated results after a counterfeit scan of your system. Either way, Antivir System PRO will attempt to scare you into purchasing the full version of Antivir System PRO.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\Antivir System PRO\antivirsystempro.exe
    2 %ProgramFiles%\Antivir System PRO\conf.cfg
    3 %ProgramFiles%\Antivir System PRO\mbase.vdb
    4 %ProgramFiles%\Antivir System PRO\quarantine.vdb
    5 %ProgramFiles%\Antivir System PRO\queue.vdb
    6 %ProgramFiles%\Antivir System PRO\uninstall.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Antivir System PROHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Antivir System PRO"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad "ieModule"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Antivir System PRO
Loading...