Home Rogue Websites Websiteblockonline.com

Websiteblockonline.com

Posted: July 20, 2010

Websiteblockonline.com is related to the Antivirus 7 cyber scam. Antivirus 7 is designed to steal money from unwary computer users. Do not click on anything when Websiteblockonline.com appears, instead remove it immediately using an updated spyware removal tool.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\[UserName]\Desktop\Antivirus7.lnk
    2 %Documents and Settings%\All Users\Start Menu\AV
    3 %Documents and Settings%\All Users\Start Menu\AV\Antivirus7.lnk
    4 %Documents and Settings%\All Users\Start Menu\AV\Uninstall.lnk
    5 %Program Files%\Antivirus7AV
    6 %Program Files%\AV
    7 %Program Files%\AV\Antivirus7.exe
    8 %ProgramFiles%\Antivirus7AV\Antivirus7.exe %ProgramFiles%\Antivirus7AV\unins000.dat
    9 %ProgramFiles%\Antivirus7AV\unins000.exe
    10 %ProgramFiles%\CommonFiles\Uninstall
    11 %ProgramFiles%\CommonFiles\Uninstall\AV
    12 %ProgramFiles%\CommonFiles\Uninstall\AV\Uninstall.lnk
    13 %WINDOWS%\system32\UpdateCheck.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\EVAACDHKEY_CURRENT_USER\Software\FNULL246HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Antivirus7"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\post platform "WinNT-EVI 25.11.2009"HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{6A23338A-C725-48D0-BA96-B12FDD22DD39}_is1
Loading...