Home Rogue Websites Best-av.info

Best-av.info

Posted: July 6, 2009

Best-av.info is a rogue website sponsoring the fake spyware remover AntivirusBEST. In order to achieve this goal, trojans infiltrate your computer through security vulnerabilities and alter the browser settings, causing web-surfing activities to be interrupted and diverted to the Best-av.info web page. Once here, your PC is subject to a fake online scan that reports fabricated infection results, all in order to scare you into purchasing the rogue spyware remover AntivirusBEST.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and settings%\All Users\Application Data\AB\ABEST.CAB
    2 %Documents and settings%\All Users\Application Data\AB\abest.exe
    3 %Documents and settings%\All Users\Application Data\AB\Installer.exe
    4 %Documents and settings%\All Users\Application Data\AB\QWProtect.dll
    5 %Documents and settings%\All Users\Application Data\AB\svchost.exe
    6 %Documents and settings%\all users\Desktop\AntivirusBEST.lnk
    7 %Documents and settings%\All Users\Start Menu\Programs\AntiVirusBEST
    8 %Documents and settings%\All users\Start Menu\Programs\antivirusbest\AntivirusBEST.lnk
    9 %Documents and settings%\All users\Start Menu\Programs\antivirusbest\Uninstall.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{44b2c9f5-608d-46de-82e1-26c5bcb85193}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{44b2c9f5-608d-46de-82e1-26c5bcb85193}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\AppID\QWProtect.dllHKEY_CLASSES_ROOT\AppID\{296a8a7f-b5ac-4789-9b33-f32c2f9a6abd}HKEY_CLASSES_ROOT\CLSID\{44b2c9f5-608d-46de-82e1-26c5bcb85193}HKEY_CLASSES_ROOT\Interface\{296a8a7f-b5ac-4789-9b33-f32c2f9a6abd}HKEY_CLASSES_ROOT\TypeLib\{684a7904-2593-4bbe-a90e-cdaf2ac606ae}HKEY_CLASSES_ROOT\qwprotect.qwprotectbhoHKEY_CLASSES_ROOT\qwprotect.qwprotectbho.1
Loading...