Home Rogue Websites Av-antispyware.com

Av-antispyware.com

Posted: April 21, 2009

Av-antispyware.com is a browser hijacker and rogue website that promotes the fake anti-spyware program AV Antispyware. Once you're on the Av-antispyware.com rogue website, your PC screen will be inundated with pop ups and alerts falsely claiming that your computer is infected. This charade is performed in order to trick you into purchasing the full paid version of the bogus AV Antispyware application. It is important to remember that these "infections" reported are imaginary and that their sole purpose is to steal your money. If you land on the Av-antispyware.com website use a reliable anti-spyware program to scan and remove the infections.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\All Users\Application Data\LastSun Ltd
    2 %Documents and Settings%\All Users\Application Data\LastSun Ltd\AV AntiSpyware\
    3 %Documents and Settings%\All Users\Application Data\LastSun Ltd\AV AntiSpyware\ava.exe
    4 %Documents and Settings%\All Users\Application Data\LastSun Ltd\AV AntiSpyware\BASE\
    5 %Documents and Settings%\All Users\Application Data\LastSun Ltd\AV AntiSpyware\DELETED\
    6 %Documents and Settings%\All Users\Application Data\LastSun Ltd\AV AntiSpyware\LOG\
    7 %Documents and Settings%\All Users\Application Data\LastSun Ltd\AV AntiSpyware\SAVED\
    8 %UserProfile%\Start Menu\Programs\AV AntiSpyware
    9 %UserProfile%\Start Menu\Programs\AV AntiSpyware\AV AntiSpyware.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\LastSun Ltd\AV AntiSpywareHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "AV AntiSpyware"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}AV AntiSpyware 1.8
Loading...