Malwaresdestructor.com

Malwaresdestructor.com Description

Malwaresdestructor.com is a browser hijacker promoting the rogue anti-spyware application known as Malware Destructor 2009. Due to affiliated trojans infiltrating the computer via security exploits and modifying the browser settings, web-surfing activitie4s are redirected to the Malwaresdestructor.com domain. Once here, the computer is subject to a fake online scan that displays fictitious and sometimes grossly exaggerated infection results, all in order to intimidate the user into purchasing the fake spyware remover Malware Destructor 2009.

Technical Information

File System Details

Malwaresdestructor.com creates the following file(s):
# File Name Detection Count
1 %UserProfile%\Recent\ANTIGEN.sys N/A
2 %UserProfile%\Recent\FW.dll N/A
3 %UserProfile%\Recent\tempdoc.exe N/A
4 %Documents and Settings%\All Users\Application Data\345d567\sqlite3.dll N/A
5 %UserProfile%\Recent\ANTIGEN.exe N/A
6 %UserProfile%\Recent\FS.sys N/A
7 %UserProfile%\Recent\PE.dll N/A
8 %Documents and Settings%\All Users\Application Data\345d567\mozcrt19.dll N/A
9 %UserProfile%\Local Settings\Temp\del.bat N/A
10 %UserProfile%\Recent\energy.exe N/A
11 %UserProfile%\Recent\hymt.exe N/A
12 %Documents and Settings%\All Users\Application Data\345d567\MD345d.exe N/A
13 %UserProfile%\Application Data\Malware Destructor 2009\Instructions.ini N/A
14 %UserProfile%\Recent\FS.tmp N/A
15 %UserProfile%\Recent\tjd.tmp N/A
16 %Documents and Settings%\All Users\Application Data\345d567 N/A
17 %Documents and Settings%\All Users\Application Data\345d567\MDestrSys\vd952342.bd N/A
18 %WINDOWS%\Temp\IMT7.xml N/A
19 %UserProfile%\Application Data\Malware Destructor 2009\cookies.sqlite N/A
20 %UserProfile%\Desktop\Malware Destructor 2009.lnk N/A
21 %UserProfile%\Recent\energy.tmp N/A
22 %UserProfile%\Recent\PE.tmp N/A
23 %UserProfile%\Start Menu\Programs\Malware Destructor 2009.lnk N/A
24 %Documents and Settings%\All Users\Application Data\345d567\MdestrSys N/A
25 %Documents and Settings%\All Users\Application Data\MDestrSys\mdestr.cfg N/A
26 %WINDOWS%\Temp\IMT9.xml N/A
27 %UserProfile%\Application Data\Malware Destructor 2009 N/A
28 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Malware Destructor 2009.lnk N/A
29 %UserProfile%\Recent\cb.drv N/A
30 %UserProfile%\Recent\kernel32.drv N/A
31 %UserProfile%\Start Menu\Malware Destructor 2009.lnk N/A
32 %Documents and Settings%\All Users\Application Data\345d567\384.mof N/A
33 %Documents and Settings%\All Users\Application Data\MdestrSys N/A
34 %WINDOWS%\Temp\IMT8.xml N/A

Registry Details

Malwaresdestructor.com creates the following registry entry or registry entries:
Registry key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft
HKEY_CLASSES_ROOT\MD345d.DocHostUIHandler
HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\