Home Malware Programs Browser Hijackers Unavsoft.com

Unavsoft.com

Posted: March 17, 2011

The malicious website Unavsoft.com is one of many malicious domains known to be used as part of the Antivirus Monitor rogue anti-malware software racket. This fake security product infects most computers through Trojans and will redirect your web browser to Unavsoft.com and block you from visiting legitimate sites. Don't make the error of assuming that Unavsoft.com or Unavsoft.com's rogue security product are genuine, since Antivirus Monitor lacks any of its advertised functions and will actually harm your security by blocking anti-malware and system diagnostic programs. Remove Unavsoft.com-related malware from your PC and you'll soon find that your computer runs much better without this kind of 'help' on it!

Unavsoft.com's Star Product - More a Hindrance Than a Helper

The majority of PC users only find themselves on Unavsoft.com after being redirected to Unavsoft.com unexpectedly, often through fake warnings that claim their computer is infected. Even a simple visit to Unavsoft.com can put your PC at risk, since the criminals behind this enterprise are known for using JavaScript and other browser exploits to force computers users to download their malware. If you're exposed to Unavsoft.com or have acquired software or malware related to Unavsoft.com, your computer may exhibit the following problems:

  • Hijacked web browsers. Malware related to Unavsoft.com will redirect your browser to Unavsoft.com by changing your search results or creating advertisements and fake unsafe website warnings with links in them. Websites belonging to real computer security companies will usually be blocked.
  • Security and system maintenance applications crashing or not opening at all. Malware from Unavsoft.com crashes real anti-malware programs to prevent you from fixing the problem in any way other than giving in to Unavsoft.com's mob-style 'protection' scheme. Antivirus Monitor infections will usually try to convince you that any program it blocks is infected, which is, of course, completely false.
  • The continual appearance of error messages that warn you about infections and other system errors that cant' be detected by known brands of security software. These threats are made up to supply a danger that encourages you to throw your money away at Unavsoft.com.
  • Antivirus Monitor and other malware linked to Unavsoft.com will 'scan' your computer and find many infections that supposedly can't be removed until you give Unavsoft.com your money! Naturally, none of these scans are real, and as a result, all they do is waste your precious time and system resources.
  • Malware from Unavsoft.com can also change various browser and system settings on a whim. The most common change tends to be altering your browser to use a bad proxy server to enable hijacking, but you may also suffer other attacks, such as a lowered firewall.

Scrubbing the Unavsoft.com Malware Out of Your Browser and Your PC

If you need access to the Internet to get the right anti-malware applications for removing Unavsoft.com software, you should reboot into Safe Mode with Networking. You can access the menu with F8 during the boot-up process; this mode stops most malware from automatically launching. You may have to change your browser settings back to prevent accidental proxy server use, however.

After getting the best security scanners with relevant updates, stay in Safe Mode for the scan. If you reboot into normal mode, you'll just give Unavsoft.com's malware a chance to attack the scan and avoid being deleted! Remember that rogue security applications that are sold by Unavsoft.com also come with Trojans in many cases, so be watchful for related malware infections along with Antivirus Monitor.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Temp%\{RANDOM CHARACTERS}
    2 %Temp%\{RANDOM CHARACTERS}\{RANDOM CHARACTERS}.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter "Enabled" = '0'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = '1'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = 'http=127.0.0.1:18810'HKEY_CURRENT_USER\Software\{RANDOM CHARACTERS}
Loading...