Home Malware Programs Browser Hijackers Antivirus-plus02.com

Antivirus-plus02.com

Posted: January 19, 2010

Antivirus-plus02.com is a browser hijacker which hacks into the system and redirects users to a corrupt website. Antivirus-plus02.com promotes the Antivirus Plus rogue security program and tries to con people into buying its license. Disregard any information on Antivirus-plus02.com. If Antivirus-plus02.com has been diverting your Internet sessions, be sure to remove the hijacker using a reliable antivirus program.

Antivirus-plus02.com has been known to persuade many computer users into downloading and installing malware. Although Antivirus-plus02.com may not be accessible at times, it is still highly suggested that computer users avoid attempting to navigate to the Antivirus-plus02.com domain. The Antivirus-plus02.com domain has been discovered to be registered to a single person according the registrar information:

Domain name: antivirus-plus02.com

Registrant Contact:
Koromodo
ben Smith
2702570544 fax: 2702570544
3073 Broaddus Avenue
McDerrriou McDerrriou 40152
ug

Administrative Contact:
ben Smith
2702570544 fax: 2702570544
3073 Broaddus Avenue
McDerrriou McDerrriou 40152
ug

DNS:
ns1.ns-srv10.com
ns2.ns-srv10.com

Created: 2009-12-26
Expires: 2010-12-26

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %WINDOWS%\system\rundll32.exe
    2 Antivirus Plus.lnk
    3 AntivirusPlus.exe
    4 C:\Documents and Settings\All Users\Start Menu\Programs\AntiVirus Plus
    5 C:\Documents and Settings\All Users\Start Menu\Programs\AntiVirus Plus\AntiVirus Plus.lnk
    6 C:\Documents and Settings\All Users\Start Menu\Programs\AntiVirus Plus\EULA.url
    7 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AntiVirus Plus.lnk
    8 C:\Documents and Settings\malwarehelp.org\Application Data\Microsoft\Internet Explorer\Quick Launch\AntiVirus Plus.lnk
    9 C:\Documents and Settings\malwarehelp.org\Desktop\AntiVirus Plus.lnk
    10 C:\Documents and Settings\malwarehelp.org\Start Menu\Programs\AntiVirus Plus
    11 C:\Documents and Settings\malwarehelp.org\Start Menu\Programs\AntiVirus Plus\AntiVirus Plus.lnk
    12 C:\Documents and Settings\malwarehelp.org\Start Menu\Programs\AntiVirus Plus\EULA.url
    13 C:\Documents and Settings\malwarehelp.org\Start Menu\Programs\Startup\AntiVirus Plus.lnk
    14 C:\Program Files\AntiVirus Plus
    15 C:\Program Files\AntiVirus Plus\AntiVirus Plus..exe
    16 C:\WINDOWS\Prefetch\ANTIVIRUS PLUS..EXE-37B6F8F6.pf
    17 Uninstall Antivirus.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\AntiVirus PlusHKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run AntiVirus Plus C:\Program Files\AntiVirus Plus\AntiVirus Plus..exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "AntivirusPlus"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run AntiVirus Plus C:\Program Files\AntiVirus Plus\AntiVirus Plus..exeHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}AntiVirus Plus_AntiVirus Plus_ DisplayIcon C:\Program Files\AntiVirus Plus\AntiVirus Plus..exeAntiVirus Plus_ InstallLocation C:\Program Files\AntiVirus Plus\

One Comment

Loading...