Threat Database Rogue Anti-Spyware Program Secure2.best-malwareprotection.net

Secure2.best-malwareprotection.net

The website secure2.best-malwareprotection.net is a malicious website, which you should not attempt to visit for any reason. If you find that your browser takes you to secure2.best-malwareprotection.net, or you have a program that claims to be anti-virus software that is directing you to secure2.best-malwareprotection.net, then your computer is infected with malware. It is very important that you do not purchase anything on the site, because secure2.best-malwareprotection.net is part of a scam.

The Purpose of Secure2.best-malwareprotection.net

Secure2.best-malwareprotection.net is a payment site for the fake anti-virus software Best Malware Protection. Among the symptoms of an infection with Best Malware Protection are fake system scans and security alerts, which will claim that Best Malware Protection has found malware on your computer. Then, Best Malware Protection will tell you that the only way to secure your computer is to pay for a license for Best Malware Protection, and Best Malware Protection will try to take you to secure2.best-malwareprotection.net, where there are a few different bogus "subscription" payment options. Supposedly, you can pay for one year of protection, two years, etc. – although, of course, you will not get any actual protection, because Best Malware Protection is fake and incapable of finding or removing threats.

If you click on one of the "Subscribe" buttons on secure2.malwareprotection.net, Best Malware Protection takes you to a page where you are supposed to choose whether you want to pay with Visa or Mastercard, and after you make that selection, you are taken to secure.newonlinepayment.com. At the check-out page on secure.newonlinepayment.com, you have the option to add several bogus security packages to your subscription, like extended online download service and Internet browsing protection. Although the amounts requested for these optional add-ons are relatively small, that doesn't make them any less fake! These phony add-ons are just what they use for bleed more money out of gullible consumers, making what would be a $50 or $60 scam into a $70 or $80 scam with very little extra effort on the part of the con-artists behind Best Malware Protection. Naturally, you should not pay for Best Malware Protection, regardless of which fake options are added on

Technical details

Although the site secure2.best-malwareprotection.net is meant to look as if it is a sub-page of another site (best-malwareprotection.net), that other, parent site does not exist. The domain name is registered, but there simply is no website at best-malwareprotection.net. One likely reason for this is that secure2.best-malwareprotection.net is hiding its actual location and origin, and using the site registration for best-malwareprotection.net to conceal an exploit server. In other words, secure2.best-malwareprotection.net is pulling its malicious content and connections from a location other than best-malwareprotection.net, and it is using the legitimate service provider for best-malwareprotection.net (in the Netherlands) in order to make it appear as if secure2.best-malwareprotection.net is trustworthy.

Furthermore, the payment site that secure2.best-malwareprotection.net will take you to, which is secure.newonlinepayment.com, is a known malicious site. Secure.newonlinepayment.com is one of several websites on a single server that provide payment service for several different fake security programs. Each rogue anti-virus application supported by this server has its own payment website, which is not the same domain as the website for the fake software. So secure.newonlinepayment.com currently services the Best Malware Protection fake security software offered on secure2.best-malwareprotection.net, but other sites on the same server support other fake security programs, and secure.newonlinepayment.com may be used in the future as a payment site for a different rogue anti-virus program scam entirely.

The gist is, secure2.best-malwareprotection.net is malicious in every way. Nothing good can come of visiting the site, and if you follow the payment process through to the end, you are handing your money and credit card information over to a bunch of crooks.

File System Details

Secure2.best-malwareprotection.net may create the following file(s):
# File Name Detections
1. C:\Documents and Settings\\Application Data\23077d\CB130_287.exe
2. %UserProfile%\Desktop\Best Malware Protection.lnk
3. %UserProfile%\Start Menu\Best Malware Protection.lnk
4. %UserProfile%\Application Data\Best Malware Protection
5. %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Best Malware Protection.lnk
6. %UserProfile%\Application Data\Best Malware Protection\cookies.sqlite
7. %UserProfile%\Application Data\Best Malware Protection\Instructions.ini
8. %UserProfile%\Start Menu\Programs\Best Malware Protection.lnk

Registry Details

Secure2.best-malwareprotection.net may create the following registry entry or registry entries:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "2" = "ekrn.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "13" = "avgchsvx.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "9" = "avgtray.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "6" = "avscan.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "10" = "avgscanx.exe"HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "5" = "avcenter.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "4" = "avgnt.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "15" = "avgwdsvc.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "12" = "avgemc.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "8" = "avgui.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun ""1" = "MSASCui.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "3" = "egui.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "14" = "avgcmgr.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "11" = "avgcfgex.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "7" = "avgfrw.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "0" = "msseces.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Run “Best Malware Protection"

Trending

Most Viewed

Loading...