Av1-best-protect.info
Av1-best-protect.info is a dangerous browser hijacker sponsoring the rogue anti-spyware application called Anti-Virus-1 (also known as Antivirus 1). Vundo trojans that infiltrate your PC through holes in your security system, modify browser settings in order to redirect your web-surfing activities to the Av1-best-protect.info domain. Once here, you are subject to a "free" - albeit completely fake - online scan, which reports - surprise, surprise - that your computer is infected! Of course, these infections are all fictitious and should not be taken seriously. All this is nothing but a scheme to intimidate you into purchasing the Anti-Virus-1 fake spyware remover.
File System Modifications
- The following files were created in the system:
# File Name 1 %Documents and Settings%\All Users\Application Data\AV1 2 %Documents and Settings%\All Users\Application Data\AV1\AV1.cab 3 %Documents and Settings%\All Users\Application Data\AV1\av1.exe 4 %Documents and Settings%\All Users\Application Data\AV1\AV1i.exe 5 %Documents and Settings%\All Users\Application Data\AV1\AV1i2.exe 6 %Documents and Settings%\All Users\Application Data\AV1\QWProtect.dll 7 %Documents and Settings%\All Users\Application Data\AV1\svchost.exe 8 %Documents and Settings%\All Users\Desktop\Anti-virus-1.lnk 9 %Documents and Settings%\All Users\Start Menu\Programs\Anti-virus-1 10 %Documents and Settings%\All Users\Start Menu\Programs\Anti-virus-1\Anti-virus-1.lnk 11 %Documents and Settings%\All Users\Start Menu\Programs\Anti-virus-1\Uninstall.lnk
Registry Modifications
- The following newly produced Registry Values are:
HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AV1HKEY_CURRENT_USER\Software\AV1\AV1\{F275E931-AFEC-4f70-B0D4-CC2731B945E0}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{70FEAD04-A7FD-4B89-B814-8A8251C90EF7}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\AppID\QWProtect.DLLHKEY_CLASSES_ROOT\AppID\{29256442-2C14-48CA-B756-3EE0F8BDC774}HKEY_CLASSES_ROOT\CLSID\{70FEAD04-A7FD-4B89-B814-8A8251C90EF7}HKEY_CLASSES_ROOT\Interface\{051C9A06-FB08-486F-B09B-8B33B261637D}HKEY_CLASSES_ROOT\QWProtect.QWProtectBHOHKEY_CLASSES_ROOT\TypeLib\{512E801E-2F02-4ADE-ACAA-58F08A22B2F8}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Monitor calibration"
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.