Home Rogue Websites Antispytag.com

Antispytag.com

Posted: October 18, 2010

Antispytag.com (Antispytag.net) is a highly dangerous rogue website related to the Antivirus Action cyber scam. Antispytag.com uses fake system scans to lure users to unknowingly perform corrupt actions on a targeted computer. Antispytag.com displays misleading scan results and then starts showing deceptive warnings claiming the PC is infected before asking users to purchase Antivirus Action as a solution. Do not fall for the blatant scam and have these rogues terminated immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Temp%\[random]\
    2 %Temp%\[random]\[random]agnz.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter "Enabled" = "0"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:33921"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random]agnz.exe"HKEY_CURRENT_USER\Software\[random]HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random]agnz.exe"
Loading...