Threat Database Rogue Websites Direct-antivirus.com

Direct-antivirus.com

Direct-antivirus.com is an untrustworthy webpage that attempts to make victims believe that their computers are at risk of malware infection. Trojans distribute Direct-antivirus.com and modify victims' browsers, redirecting them to Direct-antivirus.com. The Direct-antivirus.com webpage, warns users that they are browsing dangerous sites then recommends that they purchase Antivirus System PRO. The warnings displayed on Direct-antivirus.com are false and Antivirus System PRO is a fake security application that should be removed promptly.

File System Details

Direct-antivirus.com may create the following file(s):
# File Name Detections
1. c:\WINDOWS\system32\iehelper.dll
2. %ProgramFiles%\Antivirus System PRO\quarantine.vdb
3. %ProgramFiles%\Antivirus System PRO\mbase.vdb
4. %ProgramFiles%\Antivirus System PRO\conf.cfg
5. %ProgramFiles%\Antivirus System PRO\queue.vdb

Registry Details

Direct-antivirus.com may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Antivirus System PRO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad “ieModule”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “Antivirus System PRO”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “system tool”
HKEY_CLASSES_ROOT\CLSID\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Antivirus System PRO
HKEY_CURRENT_USER\Software\AvScan

Trending

Most Viewed

Loading...