Antick.Info

Antick.Info Description

Antick.Info is a browser hijacker promoting the distribution of the rogue anti-spyware application known as Internet Antivirus Pro. Due to affiliated trojans infiltrating the computer via security exploits and modifying the browser settings, web-surfing activities are redirected to the Antick.Info domain. Once here, the computer is subject to a fake online scan that displays fictitious and sometimes grossly exaggerated infection results, all in order to intimidate the user into purchasing and downloading the fake spyware remover Internet Antivirus Pro.

Technical Information

File System Details

Antick.Info creates the following file(s):
# File Name Detection Count
1 %LOCAL APPDATA%\Microsoft\Windows\services.exe N/A
2 iapro.exe N/A
3 %LOCAL APPDATA%\Microsoft\Internet Explorer\iv.exe N/A
4 iainstall.exe N/A
5 InternetAntivirusPro.exe N/A
6 %APPDATA%\Microsoft\Windows\winlogon.exe N/A
7 %Program Files%\Internet Antivirus Pro\iapro.exe N/A
8 install.exe N/A

Registry Details

Antick.Info creates the following registry entry or registry entries:
Registry key
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Policies\Explorer\run "iv":
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Internet Antivirus Pro
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Runonce "3p_udec_ia"
HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Run "Internet Antivirus Pro"