Avstartpc.com

By LoneStar in Browser Hijackers

Do not visit Avstartpc.com for any reason. Avstartpc.com should be regarded as a malicious website, which may be capable of harming your computer.

The Malicious Purpose of Avstartpc.com

Avstartpc.com is one of at least ten websites that promote the fake anti-virus software Virus Clear 2011. As described in another article, Virus Clear 2011 is unusual, because it has all of these payment sites that claim to be unrelated, and everything about the structure of Virus Clear 2011's sites is typical for websites that support a rogue anti-virus software scam. However, the Virus Clear 2011 malware has not emerged, and that makes it seem likely that the websites themselves play a more significant role in the scam than Virus Clear 2011 does, if it exists at all. In other words, Avstartpc.com exists to fool you, and to take your money.

Avstartpc.com offers Virus Clear 2011 for sale, with three tiers of service, starting at $49.95. The site's content is entirely fake and is designed to convince you that you should pay for Virus Clear 2011. There are phony testimonials, a really strange FAQ page that says things that don't make very much sense, and a customer support email form that requires a full credit card number in order to be submitted. Furthermore, all of these details are the same across all of the fake sites for Virus Clear 2011. Avstartpc.com is just one of many clones – and to top it off, if you trace Avstartpc.com back far enough, you'll see that Avstartpc.com is hosted in Russia, by 24ruhost, a service notorious for hosting rogue anti-virus software scam websites.

Is there a Hijacker for Avstartpc.com?

There are two or three reports from security software companies that say that Avstartpc.com is also a hijacker, a kind of infection that causes the web browser on the affected computer to redirect to a malicious website. These reports contain boilerplate, fluff text and very unusual claims about horrible things that the Avstartpc.com is supposedly capable of. However, before we jump to the conclusion that Avstartpc.com is a dangerous hijacker, it is extremely important to examine the evidence – or rather, the lack of evidence. There don't seem to be any reported cases of infection with the hijacker Avstartpc.com; there are no requests for help, no posts on message boards, and no complaints from owners of infected computers.

It is possible that the articles that claim that Avstartpc.com is a hijacker are written the way they are in anticipation of malware infections, as a way of playing it safe. After all, most of the time, when a rogue anti-virus program has payment sites, there is also a browser hijacker for each of those sites that will drive traffic to it. Nonetheless, Avstartpc.com is not an ordinary rogue anti-virus scam site, and the product Avstartpc.com claims to offer, Virus Clear 2011, is not your usual fake anti-virus program. Virus Clear 2011 still does not seem to be causing infections, and it is possible that the scam that involves Virus Clear 2011 works in a way that is fundamentally different from what most malware watchdogs are anticipating. Avstartpc.com may never emerge as a hijacker. Of course, it is possible that these two or three reports are accurate, and that Avstartpc.com has caused horrific infections on an extremely limited number of PC's, and only time will tell if that is the case. Regardless of how that may turn out, Avstartpc.com is, without a doubt, part of a scam, and that alone is a very good reason to avoid Avstartpc.com.

File System Details

Avstartpc.com may create the following file(s):
# File Name Detections
1. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = "1"
2. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:33921"

Registry Details

Avstartpc.com may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\[RANDOM CHARACTERS]
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter "Enabled" = "0"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS].exe"

Trending

Most Viewed

Loading...