Home Rogue Websites Basic-security-scan.com

Basic-security-scan.com

Posted: July 20, 2009

Basic-security-scan.com is a rogue website sponsoring the fake spyware remover called Security Mechanic. In order to achieve this goal, trojans infiltrate your computer through security vulnerabilities and alter the browser settings, causing web-surfing activities to be interrupted and diverted to the Basic-security-scan.com web page. Once here, your PC is subject to a fake online scan that reports fabricated infection results in order to scare you into purchasing the rogue spyware remover Security Mechanic.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\[User]\Application Data\SpyProtector\SC_Base_new.dat
    2 %Documents and Settings%\[User]\Application Data\SpyProtector\SC_Config.ini
    3 %ProgramFiles%\Security Mechanic
    4 %UserProfile%\Application Data\lsascs.exe
    5 %UserProfile%\Application Data\Microsoft\windll32.exe
    6 %UserProfile%\Application Data\setup.exe
    7 %UserProfile%\Application Data\shellex.dll
    8 %UserProfile%\Application Data\spyprotector
    9 %WINDOWS\System32\spyprotector.cpl

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\lsascs.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{107a1d63-2eaa-4694-8aba-ec209c630d83}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{107a1d63-2eaa-4694-8aba-ec209c630d83}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “Security Mechanic”
Loading...