Home Rogue Websites Antivirplatinum.com

Antivirplatinum.com

Posted: September 16, 2009

Antivirplatinum.com is a rogue website that is designed to advertise and sell the rogue anti-spyware program Antivirus System Pro. Through vigorous messages and literature, Antivirplatinum.com is able to convince unsuspecting computer users to download, install and ultimately purchase a fake security application such as Antivirus System Pro. Antivirplatinum.com may redirect you to the domain Antivirplatinum.microsoft.com but it is not related to Microsoft.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 iehelper.dll
    2 sysguard.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AvScanHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "system tool"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}
Loading...