Aug 31

Malware Analysis:

Antivirspace.com introduces another hijacking malware that goes side by side with Security Suite – a rogue antivirus program of high severity. Antivirspace.com turns into a big problem once the corresponding trojan virus infiltrates your computer. This little pest will do its very best to prevent you from using your machine normally. How do you like being banned from visiting sites, for example? We mean all sites. That’s precisely what Security Suite and the related malware can do to your system. The only available URL will be Antivirspace.com, and that is not a site to visit safely, we must remark. Even though Antivirspace.com is one of the many such hijackers acting in favor of Security Suite – still, it’s not a domain you should go to, especially if it jacks up your web browser badly. We assume that you found our article via a Search Engine when looking for the Antivirspace.com keyword. That’s probably because you ran into this parasite on your PC, isn’t it? Well, in that case you should be aware that you are not only dealing with a hijacker, you got way more threats on your computer as well. These are the above-mentioned trojans, Security Suite unregistered version (the so-called Security Suite demo) and a bunch of adjacent malignant items that have been taking over your machine with quite a bit of cyber confidence. You definitely need to get rid of Antivirspace.com bug – that’s exactly why we wrote this post for you so make sure you check out our help guide to lose this nasty computer infection for good.

Determine if your PC is infected with Antivirspace.com hijacker and affiliated malware (Security Suite scareware):

Antivirspace.com Screenshot:

Antivirspace.com Screenshot

Security Suite Counterfeit Warning Page Screenshot:

Antivirspace.com/block.php

How to remove Antivirspace.com hijacker manually:

To perform manual removal of Antivirspace.com hijacker and related rogue trialware, you should do the following:

Delete the following corrupt files:

  • %UserProfile%\Local Settings\Application Data\[random]
  • %UserProfile%\Local Settings\Application Data\\[random]shdw.exe

Remove Antivirspace.com related registry entries:

  • HKEY_CURRENT_USER\Software\wnxmal
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “RunInvalidSignatures” = “1″
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter “Enabled” = “0″
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyOverride” = “”
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyServer” = “http=127.0.0.1:6522″
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = “.exe”
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = “1″
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random]“
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache “%UserProfile%\Desktop\flash_player_installer\flash_player_installer.exe”
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “[random]“
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = “no”
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyEnable” =”1″

Please, note that manual removal of Antivirspace.com hijacker is a procedure of high complexity and should be performed with extreme caution. Lack of the required skills and even the slightest deviation from the instructions may lead to irreparable system damage. To ensure trouble-free deletion, it is recommended to use the automatic removal tool below:

Download Antivirspace.com Hijacker Removal Tool

Leave a Reply