Home Rogue Websites Malware-domain.com

Malware-domain.com

Posted: October 26, 2009

Malware-domain.com is a malicious domain, used to advertise the bogus anti-spyware program Alpha Antivirus. Users may be redirected to this website after the system has been affected by a Trojan horse. Malware-domain.com is, in fact, no more than a popup, which declares that the website that's presently being used is not secure and that security software is needed. The popup encourages the user to download Alpha Antivirus. Users are strongly recommended to not trust this website and remove Alpha Antivirus immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 AlphaAntivirus.exe
    2 AlphaAV.exe
    3 msnaoladdon.dll
    4 ndisapi.dll
    5 NetFilter.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Alpha AntivirusHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Alpha Antivirus”HKEY_LOCAL_MACHINE\SOFTWARE\Alpha AntivirusHKEY..\..\..\..{RegistryKeys}%UserProfile%\Desktop\Alpha Antivirus.lnkHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Alpha Antivirus
Loading...