Aug 23

Malware Analysis:

Antivirdial.com is web hoax that sugarcoats the bad intensions of its parental malware called Security Suite. Antivirdial.com is not just an online payment processor site; it also serves as a springboard for Security Suite’s scareware techniques. What we mean is – the site under consideration can be a fake warning web page (please see below). The only thing it takes Antivirdial.com to become such is a pre-defined URL tail. No matter which version of Antivirdial.com hijacker you run into (actually, you will probably ‘get to know’ both), it’s highly recommended that you take timely measures to get all the associated malware swept out of your computer. For that purpose, you should determine the source of infection that has taken over your browser. It could be that your PC has some additional threats on board which are temporarily latent but will be sure to let you know about their presence somewhat later. Antivirdial.com is not only unsafe to visit – it’s also quite a pest in terms of the financial fraud activities. It contains links to a billing processor that is a part of Security Suite propagation network. Whenever you realize you’ve been redirected to Antivirdial.com for some strange reason (or no apparent reason at all), you ought to immediately the malicious items that have definitely settled down inside your Operating System. Here are some tips for you regarding this matter.

Determine if your PC is infected with Antivirdial.com hijacker and affiliated malware (Security Suite scareware):

Antivirdial.com Screenshot:

Antivirdial.com Screenshot

Security Suite Counterfeit Warning Page Screenshot:

Antivirdial.com/block.php

How to remove Antivirdial.com hijacker manually:

To perform manual removal of Antivirdial.com hijacker and related rogue trialware, you should do the following:

Delete the following corrupt files:

  • %UserProfile%\Local Settings\Application Data\[random]
  • %UserProfile%\Local Settings\Application Data\\[random]shdw.exe

Remove Antivirdial.com related registry entries:

  • HKEY_CURRENT_USER\Software\wnxmal
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “RunInvalidSignatures” = “1″
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter “Enabled” = “0″
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyOverride” = “”
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyServer” = “http=127.0.0.1:6522″
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = “.exe”
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = “1″
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random]“
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache “%UserProfile%\Desktop\flash_player_installer\flash_player_installer.exe”
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “[random]“
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = “no”
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyEnable” =”1″

Please, note that manual removal of Antivirdial.com hijacker is a procedure of high complexity and should be performed with extreme caution. Lack of the required skills and even the slightest deviation from the instructions may lead to irreparable system damage. To ensure trouble-free deletion, it is recommended to use the automatic removal tool below:

Download Antivirdial.com Hijacker Removal Tool

Leave a Reply