Home Malware Programs Browser Hijackers Antiviric.com

Antiviric.com

Posted: March 29, 2011

Antiviric.com is a malicious website as well as a term for the web browser hijacker that redirects you to the same site. The Antiviric.com site's main claim is to tell infamy lies in Antiviric.com's promotion of rogue anti-virus products like Antivirus Monitor – applications that create false infection alerts as part of a larger scheme to steal money and information from the computer's user. All contact with Antiviric.com should be avoided since Antiviric.com may try to download harmful files onto your PC without your permission. Removing Antiviric.com-related software should be done with expediency as well as thoroughness, unless you like the idea of your browser being hijacked and real security applications crashing!

The Dangers Lurking Behind Antiviric.com's Seemingly Pleasant Site

Like most rogue security product sites, Antiviric.com tries hard to look identical to a professional security company's domain. Antiviric.com's current main product, Antivirus Monitor, may look friendly but actually comes from the same family as notorious rogue anti-virus programs like AntiVira AV. Contact with Antiviric.com can result in some or all of the following attacks on your PC:

  • Antiviric.com may display fake infection warnings and imitations of system scans when you first visit the website. These fake processes will detect malware or other system problems and request that you download Antiviric.com's signature rogue security product, thus tricking you into installing malware.
  • In some cases, Antiviric.com may not even require your permission to download and install malware – Antiviric.com may simply abuse harmful browser exploits to force a download and installation! This is more likely if you have lowered browser security settings, but no matter how high your settings are, visiting Antiviric.com remains a risk to your PC security.
  • Giving information like your credit card number or email address to Antiviric.com will result in the info being harvested for criminal purposes. Your credit card will suffer from fraudulent charges and your personal identity information may be used for identity theft crimes or as a target for spam messages.

With these dangerous possibilities in mind, you should respond to contact with Antiviric.com by immediately making a full scan of your computer for potential infections. Even visiting the entry page and immediately closing it may be enough to expose your PC to serious malware threats from Antiviric.com.

Antiviric.com's Little Insidious Helpers

Software linked to Antiviric.com is known for creating pop-ups, hijacking your web browser through Browser Helper Object exploits and blocking beneficial security applications and websites. One of the most obvious signs of Antiviric.com malware is the flagrant display of Antivirus Monitor, a rogue security program that will attempt to fake scans of your computer and create fake errors on a regular basis.

A more subtle indication of infection is if your computer's browser is consistently redirected to Antiviric.com or a similar affiliated website. This is a sign of a browser hijacker infection that's probably linked to Antiviric.com or Antivirus Monitor. Browser hijackers can also stop you from visiting anti-malware websites – be on guard if you see strange unsafe website error messages for websites that you've previously verified to be safe.

Deleting Antiviric.com malware is most convenient and likely to succeed when done by anti-malware programs due to the complexity of Antiviric.com's threats. Update your scanners for the most recent threat databases before you begin a system scan, since Antiviric.com isn't a particularly old threat and may have infections that can avoid detection by outdated scanners.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Temp%\[random]\
    2 %Temp%\[random]\[random].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = '1'HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter "Enabled" = '0'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = '1'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = '127.0.0.1:33554'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '.exe'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random]"HKEY_CURRENT_USER\Software\[random]
Loading...