Threat Database Rogue Websites Thiswebsiteisblocked.com

Thiswebsiteisblocked.com

Thiswebsiteisblocked.com is a fraudulent website that victims of browser hijacking Trojans are typically redirected to. Once a victim lands on Thiswebsiteisblocked.com, he/she will be presented with a warning page claiming that the webpage he/she was about to visit is infected. The victim will then be advised to "get security software" in order to continue browsing safely. When the victim clicks on the option to get security software he or she will be redirected to the payment page of Antivirus 7, a rogue anti-virus application. Do not waste your money on Antivirus 7 because it is a useless application.

File System Details

Thiswebsiteisblocked.com may create the following file(s):
# File Name Detections
1. %Program Files%\Antivirus7AV\unins000.exe
2. %Program Files%\Antivirus7AV\Antivirus7.exe
3. %Program Files%\AV\Antivirus7.exe
4. %WINDOWS%\system32\UpdateCheck.dll
5. %Documents and Settings%\All Users\Start Menu\AV\Uninstall.lnk
6. %Program Files%\Common Files\Uninstall
7. %Program Files%\Antivirus7AV
8. %Documents and Settings%\All Users\Start Menu\AV\Antivirus7.lnk
9. %Program Files%\AV
10. %Program Files%\Common Files\Uninstall\AV\Uninstall.lnk
11. %Documents and Settings%\All Users\Start Menu\AV
12. %Documents and Settings%\[UserName]\Desktop\Antivirus7.lnk
13. %Program Files%\Common Files\Uninstall\AV
14. %Program Files%\Antivirus7AV\unins000.dat

Registry Details

Thiswebsiteisblocked.com may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}
HKEY_CURRENT_USER\Software\FNULL246
HKEY_CLASSES_ROOT\CLSID\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\post platform "WinNT-EVI 25.11.2009"
HKEY_CURRENT_USER\Software\EVAACD
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Antivirus7"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6A23338A-C725-48D0-BA96-B12FDD22DD39}_is1

Trending

Most Viewed

Loading...