Home Malware Programs Browser Hijackers Antivirvip.net

Antivirvip.net

Posted: April 26, 2011

Antivirvip.net is a dangerous website that 'sells' the rogue security program Antivirus Protection, which is merely an elaborate scam rather than actual anti-virus software. Software linked to Antivirvip.net such as Antivirus Protection will change your desktop background, show fake infection alerts, hijack your web browser and stop you from using a wide range of applications. Avoiding Antivirvip.net at all is the first step you should take to keeping your computer safe, with the second step being the removal of Antivirvip.net-related threats by using reputable security software.

Looking Through Antivirvip.net's Pretty Shell to a Festering Core

You may be exposed to Antivirvip.net or its sister site Antivirvip.com when you click a malicious pop-up by accident, or when you visit a site that redirects you without your consent. Antivirvip.net appears to be a real security software website on the outside, but if your PC is unfortunate enough to get the Antivirus Protection infection, you'll quickly discover that the protection offered is anything but helpful.

Antivirus Protection (in some circles also known as Antivirus Trial) is a simple cut-and-paste copy of such threats as AntiVira AV, Antivirus .NET and Antivirus Monitor, with only a different name to set it apart from related malware. Both Antivirvip.net and the Antivirus Protection program itself will try hard to convince you that Antivirus Protection is a real security program, but the resulting attacks on your computer don't exactly back up their claims!

  • You may be prevented from opening applications with errors like this one:

    Security Alert
    Virus Alert!
    Application can't be started! The file [application executable] is damaged. Do you want to activate your anti-virus software now?

However, Antivirvip.net products can't detect real threats. Antivirus Protection is just stopping you from using the application to incite fear and prevent you from using anti-malware tools.

  • Antivirvip.net-related malware like Antivirus Protection will also link you to Antivirvip.net frequently and redirect your browser to Antivirvip.net on a repeated basis. You may even be prevented from visiting security-related domains or have your homepage changed to Antivirvip.net.
  • As if these very real problems weren't bad enough by themselves, Antivirvip.net's Antivirus Protection will also show misleading system scan results and fake errors that indicate high levels of system infection. Just like the above security alert, these warnings are without substance; obeying their advice just gives Antivirvip.net the opportunity to cause further havoc on your PC.

The Reaction to Antivirvip.net That Could Save Your Computer

A simple visit to Antivirvip.net measured in seconds, without any serious interaction with the site's interface, can still allow your browser to serve as unwilling gateway to a drive-by Trojan download or other attack. If you accidentally stumble across Antivirvip.net, be ready to treat your computer as infected until you've used high-quality anti-malware tools to verify the integrity of your entire system.

If you're already infected with an Antivirvip.net attacker, then the correct response is very similar but may require a bit more effort! Stop Antivirus Protection and other malware from running by using Safe Mode. If necessary, this mode will also let you use your browser without hijacks to download any required security files.

Once you're in Safe Mode, a full system scan with a top-quality anti-malware product is all you need to delete Antivirvip.net and finish off any related threats to your PC. Don't be alarmed if you experience loss of Internet connectivity or similar wide-ranging side effects; this is a common symptom of removing Antivirvip.net threats and other malware and can be undone by reverting all system settings to their normal values.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Temp%\[RANDOM CHARACTERS]\
    2 %Temp%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = '1'HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter "Enabled" = '0'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = '1'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ''HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = 'http=127.0.0.1:59274'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '.exe'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS].exe"HKEY_CURRENT_USER\Software\[RANDOM CHARACTERS]
Loading...