Antivirrt.com

By JubileeX in Browser Hijackers

Does Your Internet Browser Take You to Antivirrt.com Repeatedly?

If your Internet Browser keeps taking you to the malicious website Antivirrt.com, it is a definite sign that your computer is infected with the Antivirrt.com browser hijacker. This browser hijacker takes over the most popular Internet browsers and changes their settings, so that any online activity invariably leads to the Antivirrt.com attack website. If this is happening to you, our ESG security researchers strongly recommend that you search for any rogue security program on your computer and that you remove any unwanted invader with a legitimate and fully-updated anti-malware tool. Very often, the malware associated with the Antivirrt.com Internet browser hijacker can protect itself by blocking your security programs. In these cases, starting up Windows in Safe Mode will usually give you back control of your computer, and allow you to remove the malware behind the constant redirects towards Antivirrt.com.
 

What You Will Find at Antivirrt.com

The domain Antivirrt.com is associated with a website that distributed the rogue anti-virus program Antivirus Protection. According to our ESG malware researchers, Antivirus Protection is a dangerous program that mimics real anti-virus software. Ignore its superficially impressive design; in reality, the website at Antivirrt.com and its products are designed to steal your money by mimicking real anti-virus programs. Even if you don't buy anything at Antivirrt.com, there is a very high chance of becoming infected with malware by simply visiting this dangerous website. Even if you only visited this website for a short time, our ESG malware researchers advise running a full scan of your computer.
 

Understanding Antivirus Protection and Antivirrt.com

The criminals behind both, the rogue anti-virus program Antivirus Protection and the attack website Antivirrt.com, are actively trying to steal your money. According to our ESG security researchers, cybercriminals create rogue anti-virus programs (in this case Antivirus Protection) and set up a fake websites to showcase their fake programs. This rogue security program is designed to steal your money by deliberately causing a large number of problems on your computer, and then charging you to remove them. To raise the number of unwary users that enter their website and become exposed to the Antivirus Protection rogue security program, they also created an Internet browser hijacker (in this case Antivirrt.com) which takes over an Internet browser and directs all searches and online activity to the Antivirrt.com website. Other hackers can profit from this, through a scheme similar to legal affiliate marketing. They will use any number of means to deliver this browser hijacker into your computer (e.g. Trojans, Flash exploits, or JavaScript exploits), and then collect payment for each hit they generate on Antivirrt.com.

File System Details

Antivirrt.com may create the following file(s):
# File Name Detections
1. %Temp%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe
2. %Temp%\[RANDOM CHARACTERS]\

Registry Details

Antivirrt.com may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter "Enabled" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = 'http=127.0.0.1:59274'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS].exe"
HKEY_CURRENT_USER\Software\[RANDOM CHARACTERS]
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = "
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '.exe'

Trending

Most Viewed

Loading...