Home Malware Programs Browser Hijackers Mega-scan-pc-new14.biz

Mega-scan-pc-new14.biz

Posted: March 1, 2010

Mega-scan-pc-new14.biz is an evil website which includes a lot of Trojans and supportive rogue software downloads. The dubious website is one of the numerous domains distributing Security Essentials 2010; a bogus antivirus program. Mega-scan-pc-new14.biz uses Trojans to stealthily enter victims' operating systems. The Trojans hijack the web browsers to redirect users' Internet sessions to Mega-scan-pc-new14.biz where a scan that allegedly checks users' computers for malware activity is found. Sadly, Mega-scan-pc-new14.biz doesn't really scan users' PCs for malware infections and Security Essentials 2010 is a useless application.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\[UserName]\Application Data\[randomnumbers].exe
    2 %Documents and Settings%\[UserName]\Desktop\Security essentials 2010.lnk
    3 %Documents and Settings%\[UserName]\Start Menu\Security essentials 2010.lnk
    4 %Program Files%\Securityessentials2010\
    5 %Program Files%\Securityessentials2010\SE2010.exe
    6 %System%\smss32.exe
    7 %System%\winlogon32.exe
    8 %Temp%\[randomnumbers].dll
    9 %Temp%\[randomnumbers].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilterHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\DomainsHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktopHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\SystemHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\PhishingFilterHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\DomainsHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktopHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
Loading...