Home Rogue Websites Ezantispy.com

Ezantispy.com

Posted: September 22, 2010

Ezantispy.com is a rogue website that redirects to a fake scan page promoting Antivirus IS. Ezantispy.com may monitor browser activities and display bogus pop-up advertisements. Ezantispy.com comes bundled with a number of commercial products. Ezantispy.com will run on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter "Enabled" = "0"
    2 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = "1"
    3 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = "{local}"
    4 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5643"
    5 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "{random}"
    6 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "{random}"
Loading...