Home Malware Programs Browser Hijackers Dometype.com

Dometype.com

Posted: January 26, 2010

Dometype.com is a Browser Hijacker which promotes the rogue anti-spyware program PcsSecure. Dometype.com imitates a system scanner which runs online and pretends to perform a spyware check for the system. When the scanner ends it will generate false results to convince the user that the system has been infected. Do not fall prey to this trickery and do not click on anything associated with Dometype.com. Use an effective malware remover to detect and terminate any threats linked to Dometype.com.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\All Users\Desktop\PcsSecure.lnk
    2 %Documents and Settings%\All Users\Start Menu\Programs\PcsSecure
    3 %Documents and Settings%\All Users\Start Menu\Programs\PcsSecure\1 PcsSecure.lnk
    4 %Documents and Settings%\All Users\Start Menu\Programs\PcsSecure\2 Homepage.lnk
    5 %Documents and Settings%\All Users\Start Menu\Programs\PcsSecure\3 Uninstall.lnk
    6 %Program Files%\PcsSecure Software
    7 %Program Files%\PcsSecure Software\PcsSecure
    8 %Program Files%\PcsSecure Software\PcsSecure\PcsSecure.exe
    9 %Program Files%\PcsSecure Software\PcsSecure\uninstall.exe
    10 %WINDOWS%\10548h5c9tool4z5.exe
    11 %WINDOWS%\105z5troj199.cpl
    12 %WINDOWS%\11359not-z-9irus405.bin
    13 %WINDOWS%\system32\48fcthizf1950.cpl
    14 %WINDOWS%\system32\4943h9ckto5lz78.ocx
    15 %WINDOWS%\system32\49705hi9f896z.bin
    16 %WINDOWS%\system32\[random].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random].exe"HKEY_CURRENT_USER\Software\PcsSecureHKEY_LOCAL_MACHINE\SOFTWARE\PcsSecureHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "PcsSecure"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}PcsSecure
Loading...