Antispydrome.com

By ESGI Advisor in Browser Hijackers

Antispydrome.com Image

Please do not visit Antispydrome.com. Antispydrome.com is just another clone of the countless malicious websites that promote the fake anti-virus software Antivirus Protection. Therefore, Antispydrome.com supports an Internet-based scam, and you should not believe anything that you read on the site. Most importantly, do not download or pay for the phony software that Antispydrome.com advertises, because it is malware.

The Hijacker Antispydrome.com

In addition to being the name of the website, Antispydrome.com is also the name of the hijacker that causes the web browser on the infected computer to redirect to that site continually. When the hijacker Antispydrome.com has infected your computer, you will be unable to view any site other than Antispydrome.com. This is extremely common for a website that promotes fake security software, and all of the other clone sites that are identical to Antispydrome.com have hijackers that behave in the same way. The hijacker for Antispydrome.com may be present on your PC alone, or it may be part of an infection with the fake security application Antivirus Protection. Either way, if your computer is repeatedly taking you to Antispydrome.com instead of the websites that you try to visit, then your system is infected with malware.

The Website Antispydrome.com

Just like its hijacker, the website Antispydrome.com is nothing new. Antispydrome.com is a complete, word-for-word copy of every other bogus site that sells Antivirus Protection. Everything about it is the same, from the fake customer testimonials to the phony product description and nonexistent company address. Antispydrome.com even has an End User License Agreement (EULA) page and an email "customer support" contact form, although these don't really carry any weight, because both the company they refer to and the product they claim to support do not exist. Even the graphics on Antispydrome.com are identical to those of the other Antivirus Protection sites. Obviously, very little effort was put into the site itself, and the reason for that is that Antispydrome.com is really only valuable to its creators as a payment page for the Antivirus Protection scam.

Like every other website that promotes a fake security product, the public registration information for Antispydrome.com is false. On the surface, it looks as though Antispydrome.com is registered to a company in the United States – although even that doesn't make sense, because the website itself claims to be that of a company located in the United Kingdom. Furthermore, if you take a look at the IP address for Antispydrome.com, at present, it is 91.220.35.186. That IP address is located in Ukraine! What's worse, that address is the same one used by antivirea.net and antivirart.net, two known malicious websites that serve the Antivirus Protection fraud. Beyond a shadow of a doubt, Antispydrome.com has absolutely nothing worthwhile to offer, and there is no good reason to trust the site.

File System Details

Antispydrome.com may create the following file(s):
# File Name Detections
1. %Temp%\{RANDOM CHARACTERS}\{RANDOM CHARACTERS}.exe
2. %Temp%\{RANDOM CHARACTERS}

Registry Details

Antispydrome.com may create the following registry entry or registry entries:
[-HKEY_CLASSES_ROOT\secfile]
[HKEY_CLASSES_ROOT\.exe\shell\open\command]
[HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command]
"Content Type”=”application/x-msdownload"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter "Enabled" = '0'
[HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command]
[HKEY_CLASSES_ROOT\.exe] @=”exefile”
HKEY_CURRENT_USER\Software\{RANDOM CHARACTERS}

Trending

Most Viewed

Loading...