Home Rogue Websites Av1-best-click.info

Av1-best-click.info

Posted: April 7, 2009

Av1-best-click.info is a hijacker designed to ensure purchases of the infamous rogue anti-spyware application called Anti-Virus-1 (also known as Antivirus 1). Usually, you hit Av1-best-click.info in a few cases. The first is when your computer is infected with a Trojan that modifies your browser settings in order to redirect you to the Av1-best-click.info web page without your consent. Another probable tactic of being diverted to the Av1-best-click.info web page is from a warning page that claims you have security threats and need to eliminate them using Anti-Virus-1.

However you happen upon Av1-best-click.info, your system will be subject to a fraudulent security scan, where numerous fake infections are bound to be reported. Av1-best-click.info will then suggest you purchase and install Anti-Virus-1 in order to repair and protect your PC from future attacks. Unfortunately, this is all completely untrue, as Anti-Virus-1 neither cleans nor safeguards your computer from infection. It is best to remove Av1-best-click.info from your PC as soon as possible.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\All Users\Application Data\AV1
    2 %Documents and Settings%\All Users\Application Data\AV1\AV1.cab
    3 %Documents and Settings%\All Users\Application Data\AV1\av1.exe
    4 %Documents and Settings%\All Users\Application Data\AV1\AV1i.exe
    5 %Documents and Settings%\All Users\Application Data\AV1\AV1i2.exe
    6 %Documents and Settings%\All Users\Application Data\AV1\QWProtect.dll
    7 %Documents and Settings%\All Users\Application Data\AV1\svchost.exe
    8 %Documents and Settings%\All Users\Desktop\Anti-virus-1.lnk
    9 %Documents and Settings%\All Users\Start Menu\Programs\Anti-virus-1
    10 %Documents and Settings%\All Users\Start Menu\Programs\Anti-virus-1\Anti-virus-1.lnk
    11 %Documents and Settings%\All Users\Start Menu\Programs\Anti-virus-1\Uninstall.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AV1HKEY_CURRENT_USER\Software\AV1\AV1\{F275E931-AFEC-4f70-B0D4-CC2731B945E0}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{70FEAD04-A7FD-4B89-B814-8A8251C90EF7}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\AppID\QWProtect.DLLHKEY_CLASSES_ROOT\AppID\{29256442-2C14-48CA-B756-3EE0F8BDC774}HKEY_CLASSES_ROOT\CLSID\{70FEAD04-A7FD-4B89-B814-8A8251C90EF7}HKEY_CLASSES_ROOT\Interface\{051C9A06-FB08-486F-B09B-8B33B261637D}HKEY_CLASSES_ROOT\QWProtect.QWProtectBHOHKEY_CLASSES_ROOT\TypeLib\{512E801E-2F02-4ADE-ACAA-58F08A22B2F8}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “Monitor calibration”
Loading...