Home Malware Programs Browser Hijackers Antivirdrome.com

Antivirdrome.com

Posted: October 1, 2010

Antivirdrome.com is a corrupt website associated with the rogue called Antivirus IS. Antivirdrome.com will display fake security alerts and pop-ups in order to coerce a victim into purchasing the useless Antivirus IS. Antivirdrome.com is not to be trusted and should be removed with an up-to-date security application immediately after detection.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Local Settings\Application Data\{random}\
    2 %UserProfile%\Local Settings\Application Data\{random}\{random}.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter "Enabled" = "0'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = "1'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = "{local}"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5643'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "{random}"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "{random}"
Loading...