Home Malware Programs Browser Hijackers Eometype.com

Eometype.com

Posted: January 28, 2010

Eometype.com is a malicious Browser Hijacker which promotes the rogue anti-spyware program c. Eometype.com has the ability to produce fake system scan results to scare users into purchasing PcsSecure. Eometype.com also has the ability to redirect your browser with the help of malicious Trojans. Do not click on anything related to Eometype.com and have malware threats related to PcsSecure removed with a reliable anti-spyware program.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\All Users\Desktop\PcsSecure.lnk
    2 %Documents and Settings%\All Users\Start Menu\Programs\PcsSecure
    3 %Documents and Settings%\All Users\Start Menu\Programs\PcsSecure\1 PcsSecure.lnk
    4 %Documents and Settings%\All Users\Start Menu\Programs\PcsSecure\2 Homepage.lnk
    5 %Documents and Settings%\All Users\Start Menu\Programs\PcsSecure\3 Uninstall.lnk
    6 %Program Files%\PcsSecure Software
    7 %Program Files%\PcsSecure Software\PcsSecure
    8 %Program Files%\PcsSecure Software\PcsSecure\PcsSecure.exe
    9 %Program Files%\PcsSecure Software\PcsSecure\uninstall.exe
    10 %WINDOWS%\10548h5c9tool4z5.exe
    11 %WINDOWS%\105z5troj199.cpl
    12 %WINDOWS%\11359not-z-9irus405.bin
    13 %WINDOWS%\system32\48fcthizf1950.cpl
    14 %WINDOWS%\system32\4943h9ckto5lz78.ocx
    15 %WINDOWS%\system32\49705hi9f896z.bin
    16 %WINDOWS%\system32\[random].exe
    17 PcsSecure.exe
    18 Uninstall.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random].exe"HKEY_CURRENT_USER\Software\PcsSecureHKEY_LOCAL_MACHINE\SOFTWARE\PcsSecureHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "PcsSecure"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}PcsSecure
Loading...