Home Rogue Websites AV-Command.com

AV-Command.com

Posted: February 24, 2010

AV-Command.com is a rogue website that promotes the rogue anti-spyware program Antivirus Soft. When Antivirus Soft badware enters your computer it changes the browser settings so that everytime you go online you are redirected to AV-Command.com. AV-Command.com produces a fake system scan showing bogus results which claim your system has been infected with loads of malware. Then you will be urged to purchase Antivirus Soft to remove the alleged threats. Do not fall for this elaborate scam and use a reliable anti-spyware program to remove all the badware associated to Antivirus Soft.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random]sftav.exe
    2 %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random]sysguard.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AvScanHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5555"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random]"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random]"
Loading...