Home Rogue Websites AVProScan.com

AVProScan.com

Posted: November 11, 2008

AVProScan.com is a rogue website that hijacks your browser in order to convince you that you must purchase their phony software called Internet Antivirus. AVProScan.com tries to sell you the useless software through fake alerts stating that your computer is infected and that you must purchase their Internet Antivirus software to remove the fictitious infections.

AVProScan.com is intended to look like a computer desktop and to imitate a quick system scan of your local drive to inform you of various problems with your computer. The bogus scan will report problems such as privacy information errors, hardware errors and Trojans. Do not trust the AVProScan.com site: it is a sham. Do not purchase any software from the site. Delete the infection as soon as possible.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 duzakwq.dll
    2 gtawclv.dll
    3 icmntr.exe
    4 icthis.exe
    5 ictun.exe
    6 icun.exe
    7 isfmm.exe
    8 isfmntr.exe
    9 isfun.exe
    10 msmsgs.exe
    11 nvctrl.exe
    12 Online Security Guide.url
    13 pmmon.exe
    14 Security Troubleshooting.url
    15 spwoqbmv.exe
    16 VideoAccessCodecInstall.exe
    17 xbaqktfv.exe
    18 zafhemm.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70d17a5f-ef27-4295-90f5-20ad6f24834f}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D61D7E1A-6613-49CA-B6F9-51DB248E209D}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{aa6d4f53-4c8d-4549-84d2-02d584acc4e9}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}IExplorer Security Plug-inInternet Explorer Secure Bar
Loading...