Home
Articles
Spyware Research
Support
Scan Now
Purchase
F.A.Q.
Top 25 Spyware: About SpywareGlossary Latest Detections Fake Scanner Sites Google Search Redirects Bestclicksnow.com Bestwebsearch.com Cliccker.cn Clickover.cn Couponmountain.com Lowpriceshopper.com Mycustomsearch.cn Overclick.cn Shopica.com Shopzilla.com trafficposter.com Toseeka.com Update-browser.com Windowsclick.com Zetaclicks4.com Zoombli.com ![]() |
Malware Destructor 2011Alias: Malware Destructor 2011
Description: Posted on: September 8, 2010 09:35am Malware Destructor 2011 is a new variant of Antimalware Doctor. Malware Destructor 2011 is a fake antivirus product which hijacks your computer and uses scare tactics to get you to purchase the full version. Just like its predecessor, Malware Destructor 2011 is very good at eluding detection. In order for Malware Destructor 2011 to stop you from removing it, it disables your existing antivirus and antispyware programs and blocks access to help forums and to major name brand antispyware and antivirus vendor websites. It also disables Task Manager so that you don't shut it down manually. Additionally, Malware Destructor 2011 modifies your 'hosts' file which basically hijacks your Internet connection. This can be used to block access to certain websites, and to re-direct your searches to websites of Malware Destructor 2011's choice. Malware Destructor 2011 adds several hundred entries to your registry under the 'Image File Execution Options' key. These entries are used to block access to several hundred programs. Malware Destructor 2011 occasionally harasses the user with warnings and messages saying that their computer is infected and is under attack from hackers. In most cases we have seen, Malware Destructor 2011 was installed by a trojan or mistakenly downloaded from one of many fraudulent Fake Scanner Sites. Malware Destructor 2011 displays exaggerated fake scan results similar to those shown below: ![]() If you are unable to run programs, this is because Malware Destructor 2011 has disabled them. Malware Destructor 2011 Special Removal InstructionsPlease make sure to bookmark this page as you may need to refer back to it to complete the removal steps.We have created a modified version of SpyNoMore to handle persistent infections such as Malware Destructor 2011. Instructions below: Step 1: Click here to download the modified SpyNoMore installer onto the infected computer. If you are unable to download it directly to the infected computer, please download it to a clean computer and transfer it to the infected computer (by using a network or a flash drive). NOTE: The installer will be named iexplore.exe. Step 2: Double-click iexplore.exe to install SpyNoMore on the infected computer. When the installation is completed, SpyNoMore will check for and download available updates which will alert Malware Destructor 2011 to its presence at which point Malware Destructor 2011 may shut down SpyNoMore. Step 3: Restart SpyNoMore from the desktop shortcut then click on 'Settings' and uncheck the box that says 'Use Internet Explorer settings'. Step 4: SNM will scan your computer and if Malware Destructor 2011 is present, SNM will detect it and you will be able to see either Malware Destructor 2011 or Malware Doctor in the scan results. These two are the same product. Please note that the free version of SpyNoMore will only show you the detections but will not remove them. In order to remove the infection you need to purchase a 1-year license which costs $29 (or $39 for 3 computers). In all cases, you will be able to see Malware Destructor 2011 in the free version scan results. Step 5: Purchase the activation key from a clean computer by clicking on our Purchase link on spynomore.com. Write down the activation key and use it to activate SNM on the infected computer. This will remove Malware Destructor 2011 and restore your internet connection. You will again be able to run your programs and applications without trouble. Step 6 (optional): It would be a good idea to check your computer for rootkits (which are basically hidden trojans) which may have tagged along with Malware Destructor 2011. To do so, download and run TDSSKiller by Kaspersky Labs. Step 7 (optional): If TDSSKiller does find a rootkit, it will ask you to restart your computer so that it can remove the rootkit(s). After your computer restart, scan your computer once more with SpyNoMore to make sure everthing is OK. Threat type: Hijacker - A Hijacker is a software application that takes control of your browser's settings. Usually it changes your home page and redirects it to some unknown site or modifies your search settings. It prevents you from changing back your browser's settings. An infected browser usually operates much slower. Ransomware - Ransomware is a software application that infects a computer and asks for money to have the infection removed. Trojan - A Trojans or Trojan Horse is any programs that installs itself secretly, quite often with sinister intent. Once installed, the trojan author (hacker) can gain complete control of the infected PC. Trojans are usually designed to steal sensitive information and/or destroy the system. Trojans can be distributed as unsolicited email attachments, or bundled with freeware and shareware programs. Advice: Remove This is a very high risk threat and should be removed immediately as to prevent harm to your computer and / or to protect your privacy. Detection: SpyNoMore removes Malware Destructor 2011: Yes Threat risk: Very High Risk Extremely dangerous malware. Uses stealth installation, randomly named entries and has the capability to self update or resurrect after incomplete removal. Almost impossible to remove manually. Category mostly consists of trojans and spyware. Symptoms: Malware Destructor 2011 mysteriously appears after visiting a rogue website. Popup messages claiming that your computer is infected or is under attack. Malware Destructor 2011 is launched after system restart and stays resident in background. Right-clicking the icon does not give the option to 'exit' the program. If you try to run a program you may receive an error such as "Application cannot be launched". Running Process Signatures: N/A File Signatures: N/A Registered Dll (Dynamic Link Library) Signatures: N/A Folder Signatures: N/A Registry Signatures: N/A SpyNoMore Collected Residual File Signatures: N/A
|
|
||||