Home Rogue Websites Totalprotectav.com

Totalprotectav.com

Posted: July 25, 2011

Totalprotectav.com is a website that uses browser hijacker infections to market its rogue security program Total Protect. Totalprotectav.com's rogue security software will create fake virus warnings and other alerts to delude you into believing that a vast army of infections are on your PC, when Totalprotectav.com's real aim is to make you purchase Total Protect's nonfunctional threat-removal features. A browser hijacker that redirects you to totalprotectav.com is not only indicative of a Total Protect infection but may additionally subject you to other perils, including drive-by-download attacks and credit card fraud. Rather than treating the symptom and switching web browsers, our SpywareRemove.com malware team recommends that you treat the source of the problem and remove totalprotectav.com infections with good anti-virus software.

Telltale Signs That You Might Have a Totalprotectav.com Infection

Totalprotectav.com pretends to be a website that sells wholesome security software, but nothing could be further from the truth. Our threat analysts have discovered that Total Protect, the flagship product of totalprotectav.com, is no more than a rogue anti-spyware program without any real security-related features. Despite this inadequacy, Total Protect may still show you error messages such as this one:

Virus Detected!
This file or webpage contains malicious software.
File or Webpage: C:\Windows\System32\notepad.exe
Virus: Win32/Stuxnet.A

The above warning and all other errors that are affiliated with totalprotectav.com should be ignored, since they create false positives instead of detecting real viruses or other infections. Real anti-malware products will not find these infections, and totalprotectav.com's software only will ask you to buy the full version of Total Protect. This behavior is identical to that of other confirmed rogue security programs, such as Defender Unlimited or Bogema Security.

Buying Total Protect is the worst thing you can do, since this gives the criminals behind totalprotectav.com your credit card information, which may be abused with additional charges at random. Letting totalprotectav.com rogue anti-spyware software stay on your PC is also likely to disable your real security programs, an attack that can be avoided if you use Safe Mode or reboot from a USB drive or CD.

Keeping Your Browser from Being Railroaded by Totalprotectav.com

Our SpywareRemove.com research team has found that infections that are linked to totalprotectav.com can also cause browser hijacks. These hijacks can redirect your web browser to totalprotectav.com or force you to avoid certain websites, commonly through the following means:

  • Totalprotectav.com hijackers may set your homepage to totalprotectav.com and refuse to allow you to change it.
  • Your search results may be altered or totalprotectav.com hijackers may redirect you after you've clicked a search result link.
  • Totalprotectav.com may display fake warning messages to block websites that provide anti-malware advice or embed links that take you back to totalprotectav.com.
  • A totalprotectav.com browser hijacker may also redirect your browser at random intervals or when you type in an URL.

There's a high chance that any totalprotectav.com browser infection is also accompanied by the Total Protect rogue security program, or by a Trojan that's affiliated with rogue anti-spyware programs, such as Zlob and Fake Microsoft Security Essentials Alert. Along with these threats, most browser hijackers like totalprotectav.com will make changes to the Windows Registry. Taken together, these facts make it risky to try to remove totalprotectav.com infections without assistance from an appropriate anti-malware product.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 C:\Documents and Settings\[USER NAME]\Application Data\[RANDOM CHARACTERS]

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter "Enabled" = '0'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = '1'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = 'http=127.0.0.1:8992'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS].exe"

Technical Details

Additional Information

The following messages's were detected:
# Message
1Virus Detected! This file or webpage contains malicious software. File or Webpage: C:\Windows\System32\notepad.exe Virus: Win32/Stuxnet.A

Loading...