Dometype.com

Dometype.com is a malicious website that runs a bogus online system scan on a victim's computer. Dometype.com is distributed by browser hijacking Trojans that modify system settings to ensure that victims frequently hit Dometype.com. Once Dometype.com has completed its scan and displayed irritating pop-ups and security alerts, the victim will be advised to purchase the "full version" of PcsSecure. Both Dometype.com and PcsSecure are not to be trusted and should be removed as soon as possible.

File System Details

Dometype.com may create the following file(s):
# File Name Detections
1. %WINDOWS%\10548h5c9tool4z5.exe
2. %Program Files%\PcsSecure Software\PcsSecure\uninstall.exe
3. %WINDOWS%\system32\[random].exe
4. %Program Files%\PcsSecure Software\PcsSecure\PcsSecure.exe
5. %WINDOWS%\system32\4943h9ckto5lz78.ocx
6. %Documents and Settings%\All Users\Start Menu\Programs\PcsSecure\1 PcsSecure.lnk
7. %Program Files%\PcsSecure Software
8. %WINDOWS%\11359not-z-9irus405.bin
9. %Documents and Settings%\All Users\Start Menu\Programs\PcsSecure
10. %Documents and Settings%\All Users\Start Menu\Programs\PcsSecure\3 Uninstall.lnk
11. %WINDOWS%\105z5troj199.cpl
12. %WINDOWS%\system32\49705hi9f896z.bin
13. %Documents and Settings%\All Users\Desktop\PcsSecure.lnk
14. %Documents and Settings%\All Users\Start Menu\Programs\PcsSecure\2 Homepage.lnk
15. %Program Files%\PcsSecure Software\PcsSecure
16. %WINDOWS%\system32\48fcthizf1950.cpl

Registry Details

Dometype.com may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\PcsSecure
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PcsSecure
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "PcsSecure"
HKEY_CURRENT_USER\Software\PcsSecure
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random].exe"

Trending

Most Viewed

Loading...