Home Malware Programs Browser Hijackers An-ty-flu-service.com

An-ty-flu-service.com

Posted: December 16, 2009

An-ty-flu-service.com is a browser hijacker that uses false system scans to mislead computer users into believing that they need to download and purchase the rogue anti-spyware program referred to as Security Tool. An-ty-flu-service.com may change settings in your web browser without notification and redirecting you to a new home page. An-ty-flu-service.com is not a trusted source and should never be visited under any circumstances.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Application Data\4946550101
    2 %UserProfile%\Application Data\4946550101\4946550101.bat
    3 %UserProfile%\Application Data\4946550101\4946550101.cfg
    4 %UserProfile%\Application Data\4946550101\4946550101.exe
    5 %UserProfile%\Desktop\Security Tool.lnk
    6 %UserProfile%\Start Menu\Programs\Security Tool.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Security ToolHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "4946550101"
Loading...