Home Rogue Websites Antispy-soft.com

Antispy-soft.com

Posted: May 12, 2010

Antispy-soft.com (or Antispy-soft.net) is a malicious domain related to rogue anti-spyware application called AntiSpyware Soft. This is all part of a blatant cyberscam so do not fall for anything Antispy-soft.com produces. Remove Antispy-soft.net from your browser and terminate AntiSpyware Soft immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\[UserName]\Local Settings\Application Data\[random characters ]\[random characters]tssd.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AvScanHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" ="1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5555"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = ".exe"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random characters]"HKEY_CURRENT_USER\Software\avsoftHKEY_CURRENT_USER\Software\avsuiteHKEY_LOCAL_MACHINE\SOFTWARE\avsoftHKEY_LOCAL_MACHINE\SOFTWARE\avsuiteHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random characters]"
Loading...