Home Malware Programs Fake Warning Messages Malware.Monster.DX

Malware.Monster.DX

Posted: July 3, 2009

Malware.Monster.DX is a fake security threat used by fake spyware remover AntivirusBEST to scare you into believing your PC is infected and prompting you to purchase and download AntivirusBEST in order to combat these imaginary threats. This same fabricated parasite can also be shown as Win32.Monster.DX, and is not primarily launched by AntivirusBEST. Many other rogue spyware programs user Malware.Monster.DX to scare people.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 ABEST.CAB
    2 abest.exe
    3 AntivirusBEST.lnk
    4 installer.exe
    5 qwprotect.dll
    6 svchost.exe
    7 Uninstall.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\ABEST\ABESTHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{44B2C9F5-608D-46de-82E1-26C5BCB85193}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\AppID\QWProtect.DLLHKEY_CLASSES_ROOT\AppID\{296A8A7F-B5AC-4789-9B33-F32C2F9A6ABD}HKEY_CLASSES_ROOT\CLSID\{44B2C9F5-608D-46de-82E1-26C5BCB85193}HKEY_CLASSES_ROOT\Interface\{296A8A7F-B5AC-4789-9B33-F32C2F9A6ABD}HKEY_CLASSES_ROOT\QWProtect.QWProtectBHOHKEY_CLASSES_ROOT\QWProtect.QWProtectBHO.1HKEY_CLASSES_ROOT\TypeLib\{684A7904-2593-4BBE-A90E-CDAF2AC606AE}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "AntivirusBEST"
Loading...