Home Rogue Websites Antivir-labs.com

Antivir-labs.com

Posted: February 15, 2010

Antivir-labs.com is a rogue website designed to distribute unsafe software. Antivir-labs.com comes armed with a browser hijacker which redirects the victim Internet user to a fake system scanner with the URL Antivir-labs.com/online-scanner. This webpage pretends to scan your computer and then detects threats which are not there. Antivir-labs.com will then promote the rogue anti-spyware program Security Tool program to remove the alleged threats. Do not become another hapless victim of cyber fraud. Antivir-labs.com wants to scam you out of money. So get rid of this aggressive hijacker using a proven anti-spyware program immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Application Data\4946550101
    2 %UserProfile%\Application Data\4946550101\[random number].bat
    3 %UserProfile%\Application Data\4946550101\[random number].cfg
    4 %UserProfile%\Application Data\4946550101\[random number].exe
    5 %UserProfile%\Desktop\Security Tool.lnk
    6 %UserProfile%\Start Menu\Programs\Security Tool.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Security ToolHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random number]"
Loading...