Description is malicious website that uses a Trojan to modify the Hosts file and hijack a victim's browser. can replace the home-page, error page or search page of a victim's computer. uses a GUI almost identical to that of My Computer when displaying hard drive directories. promotes the fake anti-spyware application Antivir by redirecting victim's to a bogus scan that is conducted by Antivir. The scan will claim that the victim's computer is infected with several computer parasites that can only be removed with the purchase of the "full version" of Antivir. Users should not trust and never ever purchase Antivir.

Technical Information

File System Details creates the following file(s):
# File Name Detection Count
1 UpdateCheck.dll N/A
2 antivir.exe N/A

Registry Details creates the following registry entry or registry entries:
Registry key
%Documents and Settings%\All Users\Start Menu\AV\Uninstall.lnk
%Program Files%\Common Files\Uninstall
%Documents and Settings%\All Users\Start Menu\AV\Antivir.lnk
%Program Files%\AV\antivir.exe
%Program Files%\Common Files\Uninstall\AV\Uninstall.lnk
%Documents and Settings%\All Users\Start Menu\AV
%Program Files%\AV
%Program Files%\Common Files\Uninstall\AV