Home Malware Programs Rogue Anti-Spyware Programs Ddosclean

Ddosclean

Posted: December 21, 2010

Ddosclean (or Ddos Clean) is a rogue anti-virus program that uses Trojans to penetrate a system and misleading system scans to scare users into purchasing the program. Ddos Clean is distributed is through corrupt video codec downloads bundled with Trojans, e-mail spam attachments, fraudulent or questionable websites, misleading advertisements, malicious links found on social networks, browser hijacking attacks, corrupt search results, and other aggressive, stealthy tactics.

Ddosclean installs itself through the constant use of Trojans that creep through browser security holes to enter a system undetected. When the Trojan download is activated, it will install Ddosclean automatically before which a series of alarming bogus security alerts will bombard the Desktop. Ddos Clean will also perform a system scan and report numerous malware infections on the computer. Ddosclean's fake security alerts redirect users to a rogue website which provides the paid licensed version of the useless software.

The authors behind this rogue program have a clear and obvious strategy: to trick innocent users that they have all types of malware problems on their computer and ask payment for Ddos Clean's so-called services. Ddosclean does not have a spyware detection or removal engine, so it will not be able to remove any malware. It is highly recommended you use a reliable anti-spyware and remove Ddos Clean from your PC. Do not click on anything which seems related to this blatant scam and have Ddosclean removed immediately using a reliable malware remover.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 c:\documents and settings\{username}\Desktop\ddoscleansetup.exe
    2 c:\documents and settings\{username}\local settings\temporary internet files\Content.IE5\ISF6HJK1\ddosclean[1].exe
    3 c:\program files\ddosclean\ddosclean.exe
    4 c:\WINDOWS\system32\uninst_ddosclean.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_LOCAL_MACHINE\SOFTWARE\ddosclean]HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}ddoscleanddosclean\UninstallString
Loading...