Home Rogue Websites Theprotectall.com

Theprotectall.com

Posted: September 30, 2010

Theprotectall.com is a corrupt website related to the rogue antivirus program Antivirus IS. Theprotectall.net promotes Antivirus IS as a legitimate malware remover and runs a fake scan of the system. The scan will claim to have found malware on the system and will present Antivirus IS as a solution. Remove all threats from your PC by using an updated malware remover.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Local Settings\Application Data\{random}
    2 %UserProfile%\Local Settings\Application Data\{random}\{random}.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter "Enabled" = "0"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = "{local}"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5643"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "{random}"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "{random}"
Loading...