Home Malware Programs Rogue Anti-Virus Programs Antivir Solution Plus

Antivir Solution Plus

Posted: July 28, 2010

Antivir Solution Plus (or AntivirSolutionPlus) is a rogue anti-virus program which spreads via Trojan infections, spam emails or by using affiliated websites. Antivir Solution Plus generates fabricated pop-up alert messages and fake system scans, which report the presence of supposed infections on the user's computer. Antivir Solution Plus will bombard the user with fake alert messages, suggesting the user purchase the full version of this fake software to remove the "threats". If Antivir Solution Plus is detected in a machine, it should be terminated immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Desktop\Antivir Solution Plus.lnk
    2 %UserProfile%\Local Settings\Application Data\[random]\[random].exe
    3 %UserProfile%\Local Settings\Application Data\[random]\[random]tssd.exe
    4 AntivirSolutionPlus.exe
    5 C:\Program Files\Antivir Solution Plus

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Antivir Solution PlusHKEY_CURRENT_USER\Software\Antivir Solution PlusHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}AntivirSolutionPlus
Loading...