Home Rogue Websites Info-protector.com

Info-protector.com

Posted: March 16, 2010

Info-protector.com is another rogue website which promotes Antivirus Soft rogue antivirus software. Info-protector.com hijacks the browser and redirects hapless users to a fake scan page everytime they go online. The scan manufactures bogus results to convince the user that the PC is infected with malware. Do not click on anything related to this site or Antivirus Soft. The hackers who created this scam want you to spend unnecessarry money on this worthless product. Get an effective antivirus program to remove the threats associated to the Antivirus Soft scam.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]sftav.exe
    2 %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]sysguard.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AvScanHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5555"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random string]"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random string]"
Loading...