AntivirusBEST

AntivirusBEST is another addition to the wide range of scam security programs created by corrupt software developers to deceive computer users and obtain a profit from this illegal activities. If AntivirusBEST got into the system, it will issue false scan results detecting numerous threat found on the hard drive and ask the user to register the program to complete the removal of infections.

Failure to acquire the program may lead to more harm that leads to computer instability and malfunctions of some programs. Though buying the rogue software is not an option, it is important to remove AntivirusBEST immediately to prevent further damage on the computer.

Screen Shot Image:

antivirusbest

Technical Details and Additional Information:

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Vista

Characteristics (Analysis)
This rogue program will alter settings of Internet browser to redirect every page request to malicious web sites as follows:

  • anti-virus-best.info
  • pc-av-best.info
  • anti-virus-best.com

Malware Behavior
Counterfeit security application AntivirusBEST has a new method of deceiving computer users, and that is to display a fake Internet Explorer warning page which states that:

Internet Explorer Warning – visiting his web site may harm your computer!

Most likely causes:

The website contains exploits that can launch a malicious code on your computer
Suspicious network activity detected
There might be an active spyware running on your computer

What you can try:

Activate AntivirusBEST for secure Internet surfing (Recommended).
Check your computer for viruses and malware.
More Information

iewarn

Aside from the above fake warning, AntivirusBEST also exhibits several fake system tray pop-up that contains the following messages:

Your PC is not protected
Security center reports that “AntivirusBEST’ is inactive. Antivirus software helps protect your computer against viruses and other security threats. Click here for the suggested actions. Your system might be at rik now.

ypcini

Spyware activity alert!
Spyware.IEMonster activity detected. It is spyware that attempts to steal passwords from Internet Explorer, Mozilla Firefox, Outlook and other programs, including logins and passwords from online banking sessions, eBay, Paypal.

avbsa1

System files modification alert!
Some critical files of your computer were modified by malicious programs. It may cause system instability and data loss. Click here to block unauthorised modifications by removing threats.

Added Registry Entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "AntivirusBEST" 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{44B2C9F5-608D-46de-82E1-26C5BCB85193}
Associated Files and Folders:
c:\Documents and Settings\All Users\Application Data\AB
c:\Documents and Settings\All Users\Application Data\AB\ABEST.CAB
c:\Documents and Settings\All Users\Application Data\AB\abest.exe
c:\Documents and Settings\All Users\Application Data\AB\Installer.exe
c:\Documents and Settings\All Users\Application Data\AB\QWProtect.dll
c:\Documents and Settings\All Users\Application Data\AB\svchost.exe
c:\Documents and Settings\All Users\Desktop\AntivirusBEST.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\AntivirusBEST
c:\Documents and Settings\All Users\Start Menu\Programs\AntivirusBEST\AntivirusBEST.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\AntivirusBEST\Uninstall.lnk 

How to Remove AntivirusBEST

Automatic Removal of AntivirusBEST using Malwarebytes' Anti-Malware

In order to completely remove the threat, it is best to download and run Malwarebytes Anti-Malware. Sometimes, Trojans will block the downloading and installation of MBAM. If this happens, download it from a clean computer and rename the executable file before executing on the infected machine.