Best-av1-protect.info

Best-av1-protect.info Description

Best-av1-protect.info is a browser hijacker that promotes the rogue anti-spyware program called Anti-virus-1 (or alternatively, Antivirus 1). Through backdoor trojans that infiltrate your system and modify browser settings, you will find your web-surfing activities becoming interrupted as you are diverted to the Best-av1-protect.info web page. Here you are greeted with aggressive advertising and fraudulent online scanners that reports fictitious infection results, all in order to persuade you to purchase and install Anti-virus-1.

Technical Information

File System Details

Best-av1-protect.info creates the following file(s):
# File Name Detection Count
1 %Documents and Settings%\All Users\Application Data\AV1\AV1i2.exe N/A
2 %Documents and Settings%\All Users\Application Data\AV1\AV1i.exe N/A
3 %Documents and Settings%\All Users\Application Data\AV1\svchost.exe N/A
4 %Documents and Settings%\All Users\Application Data\AV1\av1.exe N/A
5 %Documents and Settings%\All Users\Application Data\AV1\QWProtect.dll N/A
6 %Documents and Settings%\All Users\Application Data\AV1\AV1.cab N/A
7 %Documents and Settings%\All Users\Start Menu\Programs\Anti-virus-1\Uninstall.lnk N/A
8 %Documents and Settings%\All Users\Start Menu\Programs\Anti-virus-1 N/A
9 %Documents and Settings%\All Users\Start Menu\Programs\Anti-virus-1\Anti-virus-1.lnk N/A
10 %Documents and Settings%\All Users\Application Data\AV1 N/A
11 %Documents and Settings%\All Users\Desktop\Anti-virus-1.lnk N/A

Registry Details

Best-av1-protect.info creates the following registry entry or registry entries:
Registry key
HKEY_CLASSES_ROOT\AppID\{29256442-2C14-48CA-B756-3EE0F8BDC774}
HKEY_CLASSES_ROOT\Interface\{051C9A06-FB08-486F-B09B-8B33B261637D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{70FEAD04-A7FD-4B89-B814-8A8251C90EF7}
HKEY_CURRENT_USER\Software\AV1\AV1\{F275E931-AFEC-4f70-B0D4-CC2731B945E0}
HKEY_CLASSES_ROOT\CLSID\{70FEAD04-A7FD-4B89-B814-8A8251C90EF7}
HKEY_CLASSES_ROOT\TypeLib\{512E801E-2F02-4ADE-ACAA-58F08A22B2F8}
HKEY_CURRENT_USER\Software\AV1
HKEY_CLASSES_ROOT\AppID\QWProtect.DLL
HKEY_CLASSES_ROOT\QWProtect.QWProtectBHO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Monitor calibration"