Home Rogue Websites Antispybase.com

Antispybase.com

Posted: June 21, 2010

Antispybase.com is a malicious security website that advertises AV Security Suite. Antispybase.com claims to provide a fix for multiple computer issues and malware detections; however this is all a scam. Antispybase.com was created by the same cyber crooks that created the AV Security Suite program, and it is used to trick users into purchasing this useless rogueware. Antispybase.com is a misleading website that should not be trusted.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 [random string].exe
    2 [random string]tssd.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AvSuiteHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" ="1'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5555'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = ".exe"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = "1'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random string]"HKEY_LOCAL_MACHINE\Software\AvSuiteHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random string]"
Loading...