Threat Database Adware Hematocryal.host Pop-Ups

Hematocryal.host Pop-Ups

By GoldSparrow in Adware

The Hematocryal.host domain is used to promote fake computer support services on the +844-458-6668 toll-free phone line. The Hematocryal.host domain receives Web traffic from PC users that click on misleading advertisements, and they may be under the influence of a browser hijacker program. Hematocryal.host hosts a page that appears in the URL bar as h[tt]p://hematocryal[.]host/chmx/ and loads two pop-up windows in the system foreground. This means that the pop-ups by Hematocryal.host are displayed over all other content presented on your desktop screen. The first pop-up from Hematocryal.host features the title 'We couldn't activate Windows' and is tailored to look like a Windows Activation prompt. The first notification from Hematocryal.host reads:

'We couldn't activate Windows
Try activating Windows again or contact Microsoft Support and reference the error code. You can go to Settings for more information.
Toll Free +1-844-458-6668
Error Code 0x004f014
[Close|BUTTON] [Try again|BUTTON]

The 'We couldn't activate Windows' alert from Hematocryal.host includes a background that may seem like Support.microsoft[.]com, which is the official support center for Microsoft customers. Do not call +844-458-6668 as it is not operated by certified computer support experts and it does not offer legitimate services by Microsoft Corp. Clicks on the 'We couldn't activate Windows' alerts trigger a script on h[tt]p://hematocryal[.]host/chmx/ that loads the Web browser windows in full-screen mode and a new notification to appear. The second screen message from Hematocryal.host is colored in bright red and has the title 'Windows Support Alert.' The new notification on the screen shows the following:

'Windows Support Alert
Your system detected some unusual activity.
It might harm your computer data and track your financial activities.
Please report this activity to +1-844-458-6668
[Run Windows Scan|BUTTON]'

As stated above, do not call +844-458-6668 and do not enter your Windows activation key on prompts at h[tt]p://hematocryal[.]host/chmx/. The people who created the Hematocryal.host pop-ups have no way of tracking your financial activities, and it is best to remain calm. Do not download programs from Hematocryal.host if you have clicked on the 'Run Windows Scan' button. The con artists use legitimate tools like LogMeIn and TeamViewer to gain remote desktop access when they talk with the users who call +844-458-6668. You should terminate the browser's process if you are unable to close tabs with Hematocryal.host. It is helpful to report pages similar to h[tt]p://hematocryal[.]host/chmx/ and allow browser vendors, as well as AV companies to block connections to misleading content.

Trending

Most Viewed

Loading...