rodyshop.com

By SpideyMan in Browser Hijackers

Rodyshop.com is the name of a malicious website, and of a browser hijacker. If you are not being redirected to rodyshop.com by a malware infection, please do not attempt to visit the site on your own.

Why Rodyshop.com was Created

As a website, rodyshop.com exists to support the rogue anti-virus software Antimalware Go. Rodyshop.com has just enough content to look somewhat like a real website, and rodyshop.com claims to be the site for the company that produces the Antimalware Go software. However, Antimalware Go is not real anti-virus software, but just one name for a piece of malware that is at the heart of a widespread Russian Internet scam. This malware goes by several different names, and Antimalware Go has a number of different websites that support Antimalware Go, but they are easily identified because they are identical. As Antimalware Go is a clone of AntiVira Av, rodyshop.com is a clone of AntiVira Av's sites. Rodyshop.com has the same bland color scheme, fake testimonials, and "Powerfull PC Protection" tagline. Just like the AntiVira Av sites, rodyshop.com is the payment site for the malware rodyshop.com supports. If you enter your credit card information into rodyshop.com, not only will you not get anything for your money, but you are also giving your credit card number to criminals.

The Rodyshop.com Hijacker

There is also a browser hijacker called rodyshop.com, because rodyshop.com causes the Internet browser on the infected computer to redirect to that site. In addition to constantly redirecting you to rodyshop.com, the hijacker will prevent you from accessing any other websites, and rodyshop.com will generate pop-up alerts that will say that your computer is infected with some kind of virus. In particular, the hijacker causes pop-ups that say, "Infiltration alert!" The alerts will recommend that you download a program to remove the fictitious malware. If you click on the button agreeing to the download option, you've been tricked to download the rogue program Antimalware Go. Because Antimalware Go is malware, things will only become worse than they were before if you download rodyshop.com. The hijacker can disable many of your computer's normal functions, and it is important to remove rodyshop.com as quickly as possible, but you should not trust the recommendations rodyshop.com gives you.

Detailed Information About Rodyshop.com

At the time of this writing, rodyshop.com is hosted on a dedicated server, and rodyshop.com has the IP address 91.217.162.47, which is located in Ukraine. Rodyshop.com was registered on February 23 through Bizcn.com, Inc., supposedly to a business called Rarenames, Inc., in Waltham, Massachusetts. However, because malicious websites like rodyshop.com tend to be registered with fabricated names and contact information, it is entirely likely that the exact owner of the site is not Rarenames, Inc.

File System Details

rodyshop.com may create the following file(s):
# File Name Detections
1. %Temp%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe
2. %Temp%\[RANDOM CHARACTERS\

Registry Details

rodyshop.com may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\[RANDOM CHARACTERS]
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:33921"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS].exe"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter "Enabled" = "0"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyEnable” = "1"

Trending

Most Viewed

Loading...