Home Malware Programs Browser Hijackers Av-protect.com

Av-protect.com

Posted: March 1, 2010

Av-protect.com is a website which offers the bogus Antivirus Soft security program. Av-protect.com is the same false website as Av-protect.microsoft.com; it functions as a browser hijacker. As a result, computer users are unintentionally redirected to Av-protect.com. Av-protect.com was created to illegitimately obtain the money of innocent computer users. When inside the computer system, Antivirus Soft will attempt to mislead a victim with the display of a number of pop-up warnings, bogus security alerts and fake system scans. This is part of a scam to prompt the user into purchasing Antivirus Soft in order to remove the purportedly detected malware.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]sysguard.exe
    2 %UserProfile%\Local Settings\Application Data\[random characters]\[random characters]sftav.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AvScanHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1″HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5555"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random string]"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random string]"
Loading...