Home Rogue Websites GetScanOnline.com

GetScanOnline.com

Posted: March 30, 2009

GetScanOnline.com is a web page that pretends to be an online scanner that detects parasites on your computer. GetScanOnline.com does not legitimately detect parasites but instead it promotes the rogue anti-spyware program System Security. GetScanOnline.com could contain scripts that may infect your computer with unknown parasites or a Trojan infection.

GetScanOnline.com may convince you into purchasing System Security, which is not a recommended program to have in a computer. If your computer is hijacked by GetScanOnline.com, then there is a risk to the security of your personal and financial data because GetScanOnline.com may transfer back and forth information from the infected PC which makes it a potential for data security risk. It is recommended that you remove GetScanOnline.com and System Security files immediately to prevent further harm to your computer and your privacy.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %\Documents and Settings%\All Users\Application Data\538654387
    2 %\Documents and Settings%\All Users\Application Data\538654387\1632575944.exe
    3 %\Documents and Settings%\All Users\Application Data\538654387\config.udb
    4 %\Documents and Settings%\All Users\Application Data\538654387\init.udb
    5 %\Documents and Settings%\All Users\Application Data\538654387\Languages
    6 %\Documents and Settings%\All Users\Application Data\538654387\Languages\English.lng
    7 %\Documents and Settings%\All Users\Application Data\538654387\Languages\German.lng
    8 %\Documents and Settings%\All Users\Application Data\538654387\Languages\Spanish.lng
    9 %UserProfile%\Desktop\System Security.lnk
    10 %UserProfile%\Start Menu\Programs\System Security
    11 %UserProfile%\Start Menu\Programs\System Security\System Security.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "1632575944"
Loading...