Home Malware Programs Browser Hijackers Antivirrt.com

Antivirrt.com

Posted: May 5, 2011

Antivirrt.com is both a browser hijacker and a malicious website that serves as the inevitable end destination for PC users who are attacked by the Antivirrt.com hijacker. Like many of Antivirrt.com's mirror websites, Antivirrt.com serves as a payment-processing center for the rogue anti-virus program called Antivirus Protection. Antivirus Protection can only create fake infection alerts and inaccurate scanner results; however, it isn't worth a penny of your money, let alone the high price that Antivirrt.com charges. Any contact with Antivirrt.com can expose you to other malware attacks, so you should remove any Antivirrt.com hijackers from your system as fast as you can by applying a good anti-malware program's scanning capabilities.

Antivirrt.com is Just One More Domain Shoehorned into a Wide-Spanning Con Game

Antivirrt.com isn't the only website that's trying to sell you Antivirus Protection; some others include Antivirvip.net, Antispydrome.com, Antivirvip.com, Antivirat.com, Antivirea.com and Antivirart.com. Each of these websites would like nothing more than to convince you that Antivirus Protection is a useful anti-virus product, and they may even create fake system scans and fake infection warnings to cajole you into downloading the rogue security software.

Unfortunately, Antivirus Protection is an imposter that uses a combination of false positives, browser hijacks and attacks on unrelated applications to cement Antivirrt.com's position on your hard drive. One of the most problematic symptoms of infection by Antivirrt.com-related malware like Antivirus Protection include browser hijacks, which can manifest in the following ways:

  • Fake errors that tell you that a safe website is potentially dangerous. These error pages will prevent you from accessing websites like Microsoft's own homepage or sites related to removing malware. They may also suggest that you should try to download Antivirus Protection, activate a vague 'protection' program or redirect you to malicious websites. Remember that a real browser warning will never redirect you to a strange website or request that you activate, download or purchase any kind of software.
  • Default homepage changed to Antivirrt.com You might be able to reset your homepage, but chances are high that the infection will change the homepage back to Antivirrt.com after you reboot your computer.
  • You may also be redirected to Antivirrt.com at various moments while browsing the web. This is particularly likely to happen while using a search engine, but can occur at any time, even when clicking a link that directs you to a website that isn't Antivirrt.com.

Regaining Your Browser and Your PC from Antivirrt.com

Even if you're prepared to remove Antivirrt.com hijackers and Antivirus Protection, you may find it difficult to do so. Infections related to Antivirrt.com may prevent your anti-malware programs from running by creating fake errors like this one:

Security Alert
Virus Alert!
Application can't be started! The file [application file] is damaged. Do you want to activate your anti-virus software now?

You may also acquire other infections just by having your web browser redirected to Antivirrt.com so frequently; the presence of extra malware complicates the process of cleaning your PC of Antivirrt.com threats.

However, using Safe Mode or booting in a nonstandard way (like booting from a USB device or booting a non-Windows operating system) has a high chance of putting a temporary halt to all of the above attacks. After that, you can use whatever scanner you prefer to remove Antivirrt.com threats from your PC. It should be noted that manually deleting Antivirrt.com problems, while possible, is more likely to fail unless done by an expert.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Temp%\[RANDOM CHARACTERS]\
    2 %Temp%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = '1'HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter "Enabled" = '0'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = '1'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = 'http=127.0.0.1:59274'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '.exe'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS].exe"HKEY_CURRENT_USER\Software\[RANDOM CHARACTERS]
Loading...