Anti-Virus Number 1
Anti-Virus Number 1 Description
Anti-Virus Number 1 (also known as Antivirus Number-1) is another rogue anti-spyware application. Anti-Virus Number 1 utilizes fake advertisements and pretends to be a legitimate spyware remover, though typically this parasite is installed without your knowledge using Trojan viruses that display fake alert notifications.
Once installed, Anti-Virus Number 1 is configured so that it will automatically begin running when the operating system starts up. It is then that Anti-Virus Number 1 performs fake system scans and displays various imaginary infections and security problems.
Some examples of false security threat alerts are:
“Privacy Violation alert!
Anti-Virus Number 1 detected a Privacy Violation. A program is secretly sending your private data to an untrustworthy internet host. Click here to block this activity by removing the threat (Recommended).”
“Internal Conflict alert!
Anti-Virus Number 1 detected internal software conflict. Some application tried to obtain access to system kernel (such behavior is typical of Spyware/Malware). It may cause your system to crash.”
Obviously, these kinds of security issues and infections are either greatly exaggerated or completely falsified in order to scare you into purchasing Anti-Virus Number 1, which would do absolutely nothing to help the problems your PC is facing. Remove this parasite immediately after initial appearances.
Type: Rogue AntiSpyware Programs
How Can You Detect Anti-Virus Number 1?
Anti-Virus Number 1 has typically the following processes in memory:
- c:\Documents and Settings\All Users\Application Data\AV1\svchost.exe
- C:\Windows\BasCw1RaU1oLasEc1S.exe
- c:\Documents and Settings\All Users\Application Data\AV1\av1.exe
- c:\Documents and Settings\All Users\Application Data\AV1\QWProtect.dll
- c:\Documents and Settings\All Users\Application Data\AV1\AV1i.exe
- c:\Documents and Settings\All Users\Application Data\AV1\AV1Two.exe
Anti-Virus Number 1 creates the following registry entries:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “Drives swap”
- HKEY_CLASSES_ROOT\TypeLib\{CD30B357-F8F7-4AD1-BF68-04A219D21A69}
- HKEY_CURRENT_USER\Software\AV1
- HKEY_CLASSES_ROOT\QWProtect.QWProtectBHO.1
- HKEY_CLASSES_ROOT\Interface\{0D1DBFEE-0C43-4223-8B3E-A56FB3C5C87D}
- HKEY_CLASSES_ROOT\AppID\{0D1DBFEE-0C43-4223-8B3E-A56FB3C5C87D}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D187DFF-423F-41d3-A331-A60DE5886675}
- HKEY_CLASSES_ROOT\QWProtect.QWProtectBHO
- HKEY_CLASSES_ROOT\CLSID\{8D187DFF-423F-41d3-A331-A60DE5886675}
- HKEY_CLASSES_ROOT\AppID\QWProtect.DLL
Important Article Disclaimer

Anti Virus Number 1 










