Home Malware Programs Browser Hijackers Sky-protection.com

Sky-protection.com

Posted: April 15, 2011

Sky-protection.com is a malicious website and a browser hijacker that redirects your web browser to Sky-protection.com as part of a fraud scheme. Though Sky-protection.com may externally appear to be a good security software website, Sky-protection.com actually markets rogue security programs like Malware Protection. These rogue security programs will deliver false information about your PC state of health to force you to purchase Malware Protection or another Sky-protection.com virtual product. It's recommended that you remove all software related to Sky-protection.com as soon as you can, since such threats are known for significantly reducing your browser and system security.

Sky-protection.com is Working Hand in Hand with Other Known PC Threats

The Sky-protection.com website can only successfully enact Sky-protection.com's plan of fraud with the help of other malware. The following are commonly used by malicious websites like Sky-protection.com:

  • Currently, Sky-protection.com promotes the rogue anti-malware program Malware Protection. Malware Protection will run a fake scan every time your system restarts, as well as creating various fake desktop alerts and other pop-ups. Unlike a real security program, Malware Protection will give you fake results on your system health to force you to dole out cash for a quick (and equally fake) solution.
  • Sky-protection.com and related threats will often make use of Trojans to force your PC to download other malware. This can be accomplished without the downloading activity even being visible. Such 'drive-by download' scams are particularly likely to happen if your browser security settings for JavaScript, Flash and similar functions are kept low.
  • Most infections related to either Sky-protection.com or other rogue security programs will contain a browser hijacker component. This type of infection can control what websites your browser displays and visits, even to the point of faking error messages. Since browser hijackers like Sky-protection.com typically expose the user to dangerous websites that use the above Trojan-related practices, the threat of additional contamination is high.

How to Protect Your PC from Sky-protection.com

If you choose not to delete Sky-protection.com and related malware, your web browser will be wrenched out of your control, your system security will be worsened, and Malware Protection will perpetually take up system resources alerting you to fake dangers. Removing Sky-protection.com is, therefore, strongly advised to give your computer the level of security it deserves.

Because Sky-protection.com is usually only one part of a complex threat to your PC, you should delete Sky-protection.com by using automated anti-malware software rather than attempting to delete the relevant files and Registry entries yourself. If you lack any anti-malware scanners that can rid you of Sky-protection.com, rebooting into Safe Mode with Networking should let you browse the web without hindrance to download any needed tools.

Always keep your scanner updating before running it to remove Sky-protection.com and other threats. Rogue security programs are particularly known for changing rapidly to avoid detection, and having the last possible update may make the difference between fixing your Sky-protection.com problem and failure.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\All Users\Application Data\[RANDOM CHARACTERS]\
    2 %Documents and Settings%\All Users\Application Data\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].dll
    3 %Documents and Settings%\All Users\Application Data\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe
    4 %Documents and Settings%\All Users\Application Data\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].mof
    5 %Documents and Settings%\All Users\Application Data\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].ocx
    6 %Documents and Settings%\All Users\Application Data\[RANDOM CHARACTERS]\[RANDOM CHARACTERS]\
    7 %UserProfile%\Application Data\Best Malware Protection\
    8 %UserProfile%\Application Data\Best Malware Protection\cookies.sqlite
    9 %UserProfile%\Application Data\Best Malware Protection\Instructions.ini

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Best Malware Protection"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options "Debugger" = "svchost.exe"
Loading...