Home Rogue Websites Avprotectsoft.net

Avprotectsoft.net

Posted: April 1, 2010

Avprotectsoft.net is a rogue website which hijacks the browser to promote Antivirus Soft. Avprotectsoft.net redirects users to a fake system scan page which produces false results claiming the PC is infected with malware. Soon the system will be bombarded with annoying popups warning you the purchase Antivirus Soft to solve your malware problem. Do not fall for this blatant scam and have Avprotectsoft.net and all related threats removed immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]sftav.exe
    2 %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]sysguard.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AvScanHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5555"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random string]"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random string]"
Loading...