Home Rogue Websites Windows-antivirus.net

Windows-antivirus.net

Posted: January 19, 2010

Windows-antivirus.net is a browser hijacker used solely for the promotion of the rogue anti-spyware Antivirus Live. Windows-antivirus.net will redirect users to its website and cause other security issues, makings Windows-antivirus.net removal important to the health of your computer. Take appropriate steps to counter any Windows-antivirus.net-related infections before they snowball out of control, since the threat to your system can be substantial. All products advertised by the Windows-antivirus.net infection are malware, no matter how friendly they may seem. Pay no attention to any messages, alerts, or other misdirections issued by the Windows-antivirus.net infection!

Getting to Know Windows-antivirus.net Hijacker

Windows-antivirus.net's close companionship with Antivirus Live means that the two programs are usually distributed together. Although you may already have the 'trial' version of Antivirus Live, that's not good enough for the hackers who made both pieces of malware - they want your money as well as your computer! Windows-antivirus.net is therefore just one of many heavy-handed tools meant to bring you back into contact with the website of the same name.

Upon convincing you to 'buy' Antivirus Live, you'll give your money and personal information to hackers. If it's already too late and you've made this mistake, go ahead and dispute the charges with your credit card company, and hopefully you'll be able to get the fee canceled. In worst-case scenarios, giving in to Windows-antivirus.net's demands and buying the rogue scanner will allow criminals to use your identity as they please, destroy your computer or completely drain your bank account.

Distinguishing Windows-antivirus.net from Other Hijackers

It's not especially challenging to tell Windows-antivirus.net from other malware, unless you're dealing with an excess of infections all at once. Windows-antivirus.net will redirect you towards itself rather than to any other website almost every time Windows-antivirus.net exerts control over your browser. Windows-antivirus.net will also use fake unsafe site warnings, monitor and alter your search results, and even change your homepage. You may find it completely impossible to browse the web properly with Windows-antivirus.net on your system. Other symptoms from related malware may also occur, such as pop-up advertising and alterations to your desktop.

A Safe Excising of Windows-antivirus.net

Windows-antivirus.net will use registry entries that look very similar to official Windows entries. This and other factors, such as the almost certain presence of Antivirus Live, makes hunting down each component of the malware successfully a challenge. Relying on verified anti-malware programs instead is considerably less risky. By using proven products in combination with commonsense precautions like Safe Mode, the likelihood of lasting damage to your system is very low.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Local Settings\Application Data\[random]
    2 %UserProfile%\Local Settings\Application Data\[random]\[random]sysguard.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AvScanHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DownloadHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet SettingsHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\PoliciesHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

One Comment

  • Chris says:

    2 Kudos, this really helped. You don't even have to be computer savvy to follow these instructions. Tahnks again.

Loading...