Home Rogue Websites Antivirsystem.com

Antivirsystem.com

Posted: May 7, 2009

Antivirsystem.com is a browser hijacker promoting the rogue anti-spyware application called Antivir System PRO. It achieves this goal by infiltrating your computer with affiliated trojans, which alter your browser settings in order to redirect web-surfing activities to the Antivirsystem.com domain. Here you are subject to aggressive advertising campaigns and free – albeit fake – online scans that report various fabricated infection results, all in order to fool you into purchasing and installing Antivir System PRO.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\Antivir System PRO\antivirsystempro.exe
    2 %ProgramFiles%\Antivir System PRO\conf.cfg
    3 %ProgramFiles%\Antivir System PRO\mbase.vdb
    4 %ProgramFiles%\Antivir System PRO\quarantine.vdb
    5 %ProgramFiles%\Antivir System PRO\queue.vdb
    6 %ProgramFiles%\Antivir System PRO\uninstall.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Antivir System PROHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Antivir System PRO"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad "ieModule"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Antivir System PRO
Loading...