Home Rogue Websites Spamweblist.com

Spamweblist.com

Posted: September 24, 2010

Spamweblist.com is an online threat that was found to promote and sell the rogue anti-spyware program Antivirus 7. Spamweblist.com may be presented as a help website offering tools to detect and removal malware and spyware. Spamweblist.com should not be used for any type of solution to your computer problems. Spamweblist.com was created by hackers to spread malware, mainly the program Anivirus 7 which is unable to provide the functions for detecting or removing malware.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\[UserName]\Desktop\Antivirus7.lnk
    2 %Documents and Settings%\All Users\Start Menu\AV\Antivirus7.lnk
    3 %Documents and Settings%\All Users\Start Menu\AV\Uninstall.lnk
    4 %Program Files%\Antivirus7AV\Antivirus7.exe
    5 %Program Files%\Antivirus7AV\unins000.dat
    6 %Program Files%\Antivirus7AV\unins000.exe
    7 %Program Files%\AV\Antivirus7.exe
    8 %Program Files%\Common Files\Uninstall\AV\Uninstall.lnk
    9 %WINDOWS%\system32\UpdateCheck.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\EVAACDHKEY_CURRENT_USER\Software\FNULL246HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Antivirus7"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\post platform "WinNT-EVI 25.11.2009"HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{6A23338A-C725-48D0-BA96-B12FDD22DD39}_is1
Loading...