Threat Database Browser Hijackers Sky-protection.com

Sky-protection.com

By JubileeX in Browser Hijackers

Please do not attempt to visit the website Sky-protection.com. Sky-protection.com is a malicious website. Although Sky-protection.com may look harmless at first glance, but it is only because Sky-protection.com hopes to fool you into thinking that what Sky-protection.com offers is real. Sky-protection.com is one of the sites that promotes and supports the fake anti-virus software Malware Protection.

Malware Protection is a rogue anti-virus program, which means that Sky-protection.com is a malware that pretends to be anti-virus software. Malware Protection tries to scare users of infected PCs into thinking that their computers have infections that only a "licensed" or "activated" copy of its software can remove. So at every opportunity, Malware Protection will try to get you to go to one of Malware Protection's websites, where you supposedly can purchase a software license by entering your credit card information. However, because Malware Protection is fake, there are no licenses; the whole thing is a scam. So, Sky-protection.com is one of the sites that Malware Protection will try to get you to visit in order to purchase one of these fake licenses. If your computer is infected with the rogue anti-virus program Malware Protection, you may find that your browser keeps taking you to Sky-protection.com, or that Malware Protection's pop-ups and results screens direct you to Sky-protection.com.

The Content and Background of the Website Sky-protection.com

As a website, Sky-protection.com is essentially a clone of all of the other payment sites used by the fake security programs that are related to Malware Protection. Sky-protection.com uses text and a general layout that are literally identical to that of countless other sites that promote fake anti-virus software. Overall, Sky-protection.com includes the bare minimum in content that would be required to make the site look real. There is a description of what Malware Protection supposedly can offer for your computer's security, as well as some lame, basic definitions of terminology related to malware and viruses. Sky-protection.com even has a page with a phony End User License Agreement (EULA), and an email form for customer support. To make Sky-protection.com seem as though Sky-protection.com is the website for a real company, Sky-protection.com has some icons for Facebook and Twitter, along with the heading "Follow us!" Nonetheless, there is no company to follow; there also is no support to be had, and no anti-virus software to license. Sky-protection.com exists in order to take credit card payments under fraudulent circumstances – no more, and no less.

Regardless of where Sky-protection.com may say that Sky-protection.com originates – because any company address given on the site is fake – the site actually traces back to Ukraine. Sky-protection.com's registration is Russian, and the site supposedly belongs to a private individual named Eduard Aleksandrov. Sky-protection.com has only existed since March 17, 2011, which times out with the appearance of the fake security software Malware Protection. Sky-protection.com shares an IP address with another site, which is named as if Sky-protection.com is related to Malware Protection. This other site fits a different, very malicious pattern that makes Sky-protection.com dangerous to visit.

Sky-protection.com doesn't have a leg to stand on. There is nothing legitimate, helpful, good or real about the site. Do not believe anything you see on Sky-protection.com, and if you find that your browser keeps taking you there on its own, then the bigger problem that you have is that your system has malware. Proceed with caution and don't buy into the scam.

File System Details

Sky-protection.com may create the following file(s):
# File Name Detections
1. %Documents and Settings%\All Users\Application Data\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].dll
2. %Documents and Settings%\All Users\Application Data\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe
3. %Documents and Settings%\All Users\Application Data\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].ocx
4. %Documents and Settings%\All Users\Application Data\[RANDOM CHARACTERS]\[RANDOM CHARACTERS]\
5. %UserProfile%\Application Data\Best Malware Protection\
6. %UserProfile%\Application Data\Best Malware Protection\cookies.sqlite
7. %Documents and Settings%\All Users\Application Data\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].mof
8. %UserProfile%\Application Data\Best Malware Protection\Instructions.ini
9. %Documents and Settings%\All Users\Application Data\[RANDOM CHARACTERS]\

Registry Details

Sky-protection.com may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options "Debugger" = "svchost.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Best Malware Protection"

Trending

Most Viewed

Loading...