Antivirhand.com

By Domesticus in Rogue Websites

Antivirhand.com is a deceitful website that advertises and distributes Security Suite. Once Security Suite has entered a computer system it will change the browser settings and cause the victim's browser to land on Antivirhand.com each time the victim attempts to browse the internet. Security Suite will also display fake security notifications that will redirect the victim to Antivirhand.com when clicked on. Once you remove Security Suite from your system you will stop the redirection to Antivirhand.com.

File System Details

Antivirhand.com may create the following file(s):
# File Name Detections
1. %UserProfile%\Local Settings\Application Data\\{random}shdw.exe
2. %UserProfile%\Local Settings\Application Data\{random}\

Registry Details

Antivirhand.com may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter "Enabled" = "0"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = ".exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache "%UserProfile%\Desktop\flash_player_installer\flash_player_installer.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" ="1"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:6522"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "{random}"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = "no"
HKEY_CURRENT_USER\Software\wnxmal
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "{random}"

Trending

Most Viewed

Loading...