Home Rogue Websites Miniscan4.info

Miniscan4.info

Posted: May 20, 2009

Miniscan4.info is a rogue website sponsoring the spread of the fake spyware remover Internet Antivirus Pro. In order to achieve this goal, affiliated trojans infiltrate your system via security holes and alter the browser settings, causing web-surfing activities to be diverted to the Miniscan4.info web page. Here your PC is subject to a free, albeit fake, online scan that reports false or exaggerated infection results in the hopes of scaring you into purchasing Internet Antivirus Pro.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %APPDATA%\Microsoft\Windows\winlogon.exe
    2 %LOCAL APPDATA%\Microsoft\Internet Explorer\iv.exe
    3 %LOCAL APPDATA%\Microsoft\Windows\services.exe
    4 %Program Files%\Internet Antivirus Pro\iapro.exe
    5 iainstall.exe
    6 iapro.exe
    7 install.exe
    8 InternetAntivirusPro.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Internet Antivirus ProHKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Policies\Explorer\run "iv":HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Run "Internet Antivirus Pro"HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Runonce "3p_udec_ia"
Loading...