Alpha AntiVirus
» If you can't view the screen shot (it's too small or unclear), you may have to click the screen shot when you put the mouse over the it.
» The view area is dependant upon your browser settings.
This sleek program is another to watch out for. So, don't be tricked.
It appears that the client was browsing the internet
when their browser was hijacked and redirected to another site.
Below are entries found in the Registry(If you are unfamiliar with the registry...Leave this page NOW)
and files associated with the program.
SEE MORE IMAGES BELOW
-
Key Name: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Class Name:
Last Write Time:
Value 0
Name:
Type: REG_SZ
Data: ""
-
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AlphaAnt
Name: Id
Type: REG_SZ
Data: {51FDC6A1-DCBD-48A2-BF1F-9C4010EF9477}
- HKEY_USERS\ttt-sof\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures
Name: AlphaAnt.job.fp
Type: REG_DWORD
Data: 0xa74****
- HKEY_USERS\S-1-5-21-****-****-*****-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\AlphaAnt
Name: DisplayIcon
Type: REG_SZ
Data: C:\Program
Files\AlphaAnt\alpha.exe
Value 1
Name:
DisplayName
Type: REG_SZ
Data: Alpha Antivirus
Value
2
Name: UninstallString
Type: REG_SZ
Data: C:\Program
Files\AlphaAnt\alpha.exe -uninst
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\AlphaAnt
Name: DisplayIcon
Type:
REG_SZ
Data: C:\Program Files\AlphaAnt\alpha.exe
Value
1
Name: DisplayName
Type: REG_SZ
Data: Alpha
Antivirus
Value 2
Name: UninstallString
Type:
REG_SZ
Data: C:\Program Files\AlphaAnt\alpha.exe -uninst
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
" Alpha AntiVirus"
You will find shortcuts to the program in the c:\Program Files\Common Files\AlphaAntUninstall folder:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
The following is a list of files you may find in the:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
"c:\Program Files\AlphaAnt" Folder
Size
Name
- 1,289,728 bytes » alpha.exe
- check the user feed, too
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
The following is a list of files you may find in the:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
"c:\windows\tasks" Folder
Size
Name
- 226 bytes » AlphaAnt.job
Remember to always check here:
C:\WINDOWS\Prefetch
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
-

-

-

-

-

START OVER