Home Rogue Websites Antispywareon.net

Antispywareon.net

Posted: April 20, 2011

ScreenshotAntispywareon.net is just one of many malicious websites that make a profit by promoting rogue anti-virus programs. The product 'sold' by Antispywareon.net, Antivirus Protection, is an infection that causes a variety of problems for your computer, most notably fake error messages and similar false positive alerts. You should remove Antispywareon.net-related malware as soon as you can, and avoid contact with Antispywareon.net. Rogue security product-promoting websites like Antispywareon.net may try to encourage you to download malware such as browser hijackers and are capable of forcing malware onto your PC through the abuse of browser exploits.

Antispywareon.net is More Anti-Computer than Anti-Spyware

At first glance, Antispywareon.net may appear to be a real security software website, with testimonials and data that tell you how wonderful their Antivirus Protection product is. Nonetheless, peering closer will quickly show you that Antispywareon.net is actually nothing more than a portal for malware and processing fraudulent credit card payments. Antispywareon.net also has at least one counterpart, Antispywareon.com, which serves the same functions for a differently-named version of the rogue security program.

Even the Antivirus Protection program is itself just a copy of other known threats – its attacks and overall behavior are strongly reminiscent of Antivirus Monitor, AntiVira AV, Antimalware GO and Antivirus .NET, among others. If you're infected by Antispywareon.net's Antivirus Protection or another rogue security program, keep in mind that the numerous error pop-ups and horrible scanner results you're being treated to are all false. Here are some of the most noticeable fake errors you may see:

Antivirus software alert
Infiltration alert
Your computer is being attacked by an Internet virus. It could be password-stealing attack, a Trojan-dropper or similar.

Windows Security Alert
Windows reports that computer is infected. Antivirus software helps to protect your computer against viruses and other security threats. Click here for the scan your computer. Your system might be at risk now.

Security Alert
Virus Alert!
Application can't be started! The file [application executable file] is damaged. Do you want to activate your anti-virus software now?

Antispywareon.net malware infections may also use these errors in conjunction with causing crashes and other malfunctions in legitimate, uninfected applications. Don't be fooled into thinking you have countless infections when Antispywareon.net's so-called 'product' is the only problem on your computer!

The Web Browser-Enslaving Side of Antispywareon.net

In addition to the many other attacks you may face from Antispywareon.net malware, web browser hijacks are a common problem. These hijacks operate by inserting entries into your Registry that force your browser to use a proxy server. Afterwards, your homepage and search results will be set to Antispywareon.net.

You may also be unable to visit other websites due to strange error messages. These errors are also fake, but imitate the appearance of legitimate unsafe website errors, as you can see with the below example:

Internet Explorer Warning - visiting this web site may harm your computer!
Most likely causes:
– The website contains exploits that can launch a malicious code on your computer
– Suspicious network activity detected
– There might be an active spyware running on your computer

To regain control over your web browser and the rest of your PC, you should first stop Antispywareon.net programs from running by rebooting into Safe Mode with Networking. After this, you can delete Antispywareon.net infections by updating and running your choice of genuine anti-malware scanner.

Remember to avoid any unnecessary contact with Antispywareon.net and other unsafe websites until you've finished removing all Antispywareon.net-related infections. Even just a few seconds spent at Antispywareon.net without clicking anything can expose you to Trojans and other PC threats!

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Temp%\[RANDOM CHARACTERS]\
    2 %Temp%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = '1'HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter "Enabled" = '0'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = '1'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = 'http=127.0.0.1:59274'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '.exe'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS].exe"HKEY_CURRENT_USER\Software\[RANDOM CHARACTERS]
Loading...