Home Rogue Websites Av1-best-protect.info

Av1-best-protect.info

Posted: April 23, 2009

Av1-best-protect.info is a dangerous browser hijacker sponsoring the rogue anti-spyware application called Anti-Virus-1 (also known as Antivirus 1). Vundo trojans that infiltrate your PC through holes in your security system, modify browser settings in order to redirect your web-surfing activities to the Av1-best-protect.info domain. Once here, you are subject to a "free" - albeit completely fake - online scan, which reports - surprise, surprise - that your computer is infected! Of course, these infections are all fictitious and should not be taken seriously. All this is nothing but a scheme to intimidate you into purchasing the Anti-Virus-1 fake spyware remover.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\All Users\Application Data\AV1
    2 %Documents and Settings%\All Users\Application Data\AV1\AV1.cab
    3 %Documents and Settings%\All Users\Application Data\AV1\av1.exe
    4 %Documents and Settings%\All Users\Application Data\AV1\AV1i.exe
    5 %Documents and Settings%\All Users\Application Data\AV1\AV1i2.exe
    6 %Documents and Settings%\All Users\Application Data\AV1\QWProtect.dll
    7 %Documents and Settings%\All Users\Application Data\AV1\svchost.exe
    8 %Documents and Settings%\All Users\Desktop\Anti-virus-1.lnk
    9 %Documents and Settings%\All Users\Start Menu\Programs\Anti-virus-1
    10 %Documents and Settings%\All Users\Start Menu\Programs\Anti-virus-1\Anti-virus-1.lnk
    11 %Documents and Settings%\All Users\Start Menu\Programs\Anti-virus-1\Uninstall.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AV1HKEY_CURRENT_USER\Software\AV1\AV1\{F275E931-AFEC-4f70-B0D4-CC2731B945E0}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{70FEAD04-A7FD-4B89-B814-8A8251C90EF7}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\AppID\QWProtect.DLLHKEY_CLASSES_ROOT\AppID\{29256442-2C14-48CA-B756-3EE0F8BDC774}HKEY_CLASSES_ROOT\CLSID\{70FEAD04-A7FD-4B89-B814-8A8251C90EF7}HKEY_CLASSES_ROOT\Interface\{051C9A06-FB08-486F-B09B-8B33B261637D}HKEY_CLASSES_ROOT\QWProtect.QWProtectBHOHKEY_CLASSES_ROOT\TypeLib\{512E801E-2F02-4ADE-ACAA-58F08A22B2F8}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Monitor calibration"
Loading...