Best-av.info

Best-av.info Description

Best-av.info is a browser hijacker promoting the rogue anti-spyware application known as AntivirusBEST. Due to affiliated trojans infiltrating the computer via security exploits and modifying the browser settings, web-surfing activities are redirected to the Best-av.info domain. Once here, the computer is subject to a fake online scan that displays fictitious and sometimes grossly exaggerated infection results, in order to intimidate the user into purchasing the fake spyware remover AntivirusBEST.

Technical Information

File System Details

Best-av.info creates the following file(s):
# File Name Detection Count
1 %Documents and settings%\All Users\Application Data\AB\QWProtect.dll N/A
2 %Documents and settings%\All Users\Application Data\AB\Installer.exe N/A
3 %Documents and settings%\All Users\Application Data\AB\abest.exe N/A
4 %Documents and settings%\All Users\Application Data\AB\svchost.exe N/A
5 %Documents and settings%\All users\Start Menu\Programs\antivirusbest\Uninstall.lnk N/A
6 %Documents and settings%\All users\Start Menu\Programs\antivirusbest\AntivirusBEST.lnk N/A
7 %Documents and settings%\all users\Desktop\AntivirusBEST.lnk N/A
8 %Documents and settings%\All Users\Start Menu\Programs\AntiVirusBEST N/A
9 %Documents and settings%\All Users\Application Data\AB\ABEST.CAB N/A

Registry Details

Best-av.info creates the following registry entry or registry entries:
Registry key
HKEY_CLASSES_ROOT\Interface\{296a8a7f-b5ac-4789-9b33-f32c2f9a6abd}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{44b2c9f5-608d-46de-82e1-26c5bcb85193}
HKEY_CLASSES_ROOT\AppID\QWProtect.dll
HKEY_CLASSES_ROOT\TypeLib\{684a7904-2593-4bbe-a90e-cdaf2ac606ae}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{44b2c9f5-608d-46de-82e1-26c5bcb85193}
HKEY_CLASSES_ROOT\AppID\{296a8a7f-b5ac-4789-9b33-f32c2f9a6abd}
HKEY_CLASSES_ROOT\qwprotect.qwprotectbho
HKEY_CLASSES_ROOT\CLSID\{44b2c9f5-608d-46de-82e1-26c5bcb85193}
HKEY_CLASSES_ROOT\qwprotect.qwprotectbho.1