Home Malware Programs Browser Hijackers Customwebblacklist.com

Customwebblacklist.com

Posted: June 22, 2010

Customwebblacklist.com (or Customwebblacklist.net) is a corrupt domain related to the rogue antispyware program Antivirus 7. Customwebblacklist.com hijacks the browser and redirects it to a fake scan page which claims the PC is infected with malware. Do not fall for this trickery and have Customwebblacklist.com and Antivirus 7 removed using a reliable ant-spyware product.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\[UserName]\Desktop\Antivirus7.lnk
    2 %Documents and Settings%\All Users\Start Menu\AV
    3 %Documents and Settings%\All Users\Start Menu\AV\Antivirus7.lnk
    4 %Documents and Settings%\All Users\Start Menu\AV\Uninstall.lnk
    5 %Program Files%\Antivirus7AV
    6 %Program Files%\Antivirus7AV\Antivirus7.exe
    7 %Program Files%\Antivirus7AV\unins000.dat
    8 %Program Files%\Antivirus7AV\unins000.exe
    9 %Program Files%\AV
    10 %Program Files%\AV\Antivirus7.exe
    11 %Program Files%\Common Files\Uninstall
    12 %Program Files%\Common Files\Uninstall\AV
    13 %Program Files%\Common Files\Uninstall\AV\Uninstall.lnk
    14 %WINDOWS%\system32\UpdateCheck.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\EVAACDHKEY_CURRENT_USER\Software\FNULL246HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Antivirus7"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\post platform "WinNT-EVI 25.11.2009"HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{6A23338A-C725-48D0-BA96-B12FDD22DD39}_is1
Loading...