Home Rogue Websites Omegantivir.com

Omegantivir.com

Posted: June 21, 2010

Omegantivir.com is a malicious website which promotes the rogue anti-spyware program called AV Security Suite. A user won't encounter Omegantivir.com unless his/her computer system has been corrupted by AV Security Suite. Omegantivir.com can be inserted into a user's Hosts file by malicious Trojans associated with AV Security Suite. The trial version of AV Security Suite will display a lot of security alerts and make a victim's computer impossible to use. When a user clicks on the pop-up alerts or opens his/her IE browser, he/she will be redirected to Omegantivir.com and coerced into purchasing the non-existent "full version" of AV Security Suite. Do not waste your money on AV Security Suite and do not believe anything on Omegantivir.com.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]tssd.exe
    2 [random string].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AvSuiteHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" ="1'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5555'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = ".exe"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = "1'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random string]"HKEY_LOCAL_MACHINE\Software\AvSuiteHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random string]"
Loading...