Home Rogue Websites Totalsolutionantivirus.com

Totalsolutionantivirus.com

Posted: September 23, 2011

Totalsolutionantivirus.com is a fake website that promotes the rogue anti-virus program Total Protect (also known as Total Protect Antivirus Solution and Total Protect 2011). SpywareRemove.com malware research team has found that Totalsolutionantivirus.com's Total Protect product is completely bereft of genuine anti-virus features and can only create the standard types of fake warning messages that you would see from other types of scamware. Totalsolutionantivirus.com's arsenal of attacks includes fake alerts that try to force you to install Total Protect, as well as browser hijackers that redirect you to Totalsolutionantivirus.com regardless of what websites you may be viewing at the time. Although any contact with Totalsolutionantivirus.com should be considered a potential vector for infection, you can remove Totalsolutionantivirus.com software from your PC with genuine computer security products.

Why a Detour to Totalsolutionantivirus.com May Cost You More Than Your Time

Most victims of Totalsolutionantivirus.com-related attacks will only find themselves at Totalsolutionantivirus.com after they've been infected with a browser hijacker. Typical symptoms of Totalsolutionantivirus.com browser hijacks that SpywareRemove.com malware experts have noted can include pop-ups, redirects to Totalsolutionantivirus.com, having your homepage locked to Totalsolutionantivirus.com or blocked PC security websites access.

Although Totalsolutionantivirus.com looks like a normal software website, Totalsolutionantivirus.com's 'support' features aren't functional, and Totalsolutionantivirus.com's reputation is one of marketing Total Protect features that, in reality, aren't in evidence. SpywareRemove.com malware analysts have noted that, in addition to containing a fake scanner on the site, Totalsolutionantivirus.com will also prompt you on Totalsolutionantivirus.com's own to install Total Protect by warning you about infections that Totalsolutionantivirus.com could remove.

Due to the confirmed fraudulent nature of Total Protect and Totalsolutionantivirus.com itself, it's strongly encouraged that you scan your PC for potential infections after you've had any contact with Totalsolutionantivirus.com. Although Totalsolutionantivirus.com browser hijacker symptoms may manifest within your web browser, uninstalling or altering your web browser program isn't a substitute for deleting Totalsolutionantivirus.com software with a good anti-malware product.

Attacks from Totalsolutionantivirus.com Software That You Should Be Ready to Deflect

Because even a single visit to Totalsolutionantivirus.com without any interaction with Totalsolutionantivirus.com's interface can still expose you to drive-by-download attacks and Total Protect installations, you should also be aware of the basic properties of scamware like Total Protect. SpywareRemove.com malware researchers note that the following attacks are especially likely after your PC has been infected by Totalsolutionantivirus.com:

  • Fake infection alerts and other types of inaccurate system messages. Total Protect uses these alerts to encourage you to spend money at Totalsolutionantivirus.com, but since Total Protect isn't capable of detecting real PC threats, there's no point in following Totalsolutionantivirus.com's advice.
  • Total Protect will launch itself without your permission and will remain active even if you attempt to close it. This allows Total Protect to engage in browser-hijacking attacks and block websites that could assist you with removing Totalsolutionantivirus.com software.
  • A desktop image that's been changed to a fake warning message. As is true of Total Protect's other warnings, this message is fraudulent and shouldn't be considered an accurate representation of your computer's health.

You can delete Totalsolutionantivirus.com software with a little help from the actual anti-malware software that Total Protect pretends to be, although using Safe Mode or similar methods to disable Total Protect may be necessary for total removal.

Technical Details

File System Modifications

The following files were created in the system:



%AppData%\RtlDriver32.exe File name: %AppData%\RtlDriver32.exe
File type: Executable File
Mime Type: unknown/exe

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKCU\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS]"
Loading...