Home Malware Programs Adware AltoNav Ads

AltoNav Ads

Posted: October 6, 2015

Threat Metric

Ranking: 14,683
Threat Level: 2/10
Infected PCs: 5,319
First Seen: September 23, 2015
Last Seen: February 23, 2025
OS(es) Affected: Windows

If you somehow find yourself on the official site of AltoNav, you may assume it is a reliable browser assistant. Its developers state that the tool can be of great help to you by fixing your typos and web address errors. Moreover, the AltoNav should allegedly assist you in finding the best online deals for you. In reality, this add-on is adware that works similarly to TruNavi, which is a product of the same software developer. Just like TruNavi and many other ad-oriented plugins, AltoNav may enter alongside freeware. The fact that the frequently selected 'Quick' guide doesn't provide detailed data about the bonus components is the reasons some users cannot recall installing AltoNav. The adware may cause more than a few changes to web clients. The first that will catch your attention when you launch Google Chrome, Mozilla Firefox or Internet Explorer is a homepage that you haven't set manually. If it is an unknown search site, you should not use it because it may display inaccurate results to make you visit partner sites. The adware also may be responsible for the creation of large amounts of commercial materials in various forms. The people behind AltoNav may benefit from pop-ups, banners, animations and video commercials. Even ordinary words in the text may be transformed into links that lead towards third-party affiliate pages. As you can expect, the presence of so many unrequested ads may be annoying. What you may not know, however, is that some of the discounts and coupons that you see may be unsafe. Clicking on them, there is a chance to find yourself on fraudulent or potentially malicious platforms. The plugin may be hard to disable manually because it may become active as soon as you launch your browser again. To delete it efficiently, the experts recommend using special security software.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%WINDIR%\System32\Altonv64.dll%WINDIR%\SysWOW64\Altonv.dll%WINDIR%\Temp\Altonv[RANDOM CHARACTERS].logHKEY..\..\..\..{RegistryKeys}Software\AltonavSOFTWARE\Classes\AppID\Altonv.EXESOFTWARE\Classes\Wow6432Node\AppID\Altonv.EXESOFTWARE\Microsoft\Tracing\Altonav_RASAPI32SOFTWARE\Microsoft\Tracing\Altonav_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\Run\Altonav TraySOFTWARE\Wow6432Node\AltonavSOFTWARE\Wow6432Node\Classes\AppID\Altonv.EXESOFTWARE\Wow6432Node\Dyn\Installed\AltonavSOFTWARE\Wow6432Node\Microsoft\Tracing\Altonav_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\Altonav_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Altonav TraySYSTEM\ControlSet001\Control\SafeBoot\Network\AltonvSYSTEM\ControlSet001\services\AltonavV1SYSTEM\ControlSet001\services\AltonavV2SYSTEM\ControlSet001\services\AltonvSYSTEM\ControlSet001\services\eventlog\Application\PlsvcV2SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AltonvSYSTEM\CurrentControlSet\services\AltonavV1SYSTEM\CurrentControlSet\services\AltonavV2SYSTEM\CurrentControlSet\services\AltonvSYSTEM\CurrentControlSet\services\eventlog\Application\PlsvcV2HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Altonav

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Altonav%PROGRAMFILES%\Altonav%PROGRAMFILES(x86)%\Altonav
Loading...