Home Rogue Websites Ms-scan.net

Ms-scan.net

Posted: April 13, 2009

Ms-scan.net is a hijacker website that pretends to be a legitimate scanner. Ms-scan.net is actually a site designed to promote the rogue antispyware program System Protector. Ms-scan.net may automatically install System Protector on your computer in order to force users to purchase a full version of the program. It is not advisable to purchase System Protector or any other program listed on the Ms-scan.net site. Ms-scan.net popups up several annoying messages on your screen which will continue until you've removed System Protector and Ms-scan.net completely from your computer.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Program Files%\System Protector
    2 %UserProfile%\Application Data\install.exe
    3 %UserProfile%\Application Data\lsascs.exe
    4 %UserProfile%\Application Data\Microsoft\windll32.exe
    5 %UserProfile%\Application Data\shellex.dll
    6 %UserProfile%\Application Data\SpyProtectorSC_Base_new.dat
    7 %UserProfile%\Application Data\SpyProtectorSC_Config.ini
    8 %UserProfile%\Desktop\System Protector.lnk
    9 %UserProfile%\Start Menu\Programs\System Protector\Purchase License.url
    10 %UserProfile%\Start Menu\Programs\System Protector\Support Page.url
    11 %UserProfile%\Start Menu\Programs\System Protector\System Protector.lnk
    12 %WINDOWS%\system32\spyprotector.cpl

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" => 1HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\System ProtectorHKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\System ProtectorHKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{107A1D63-2EAA-4694-8ABA-EC209C630D83}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\System ProtectorHKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellexHKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\System ProtectorHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\lsascs.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "System Protector"
Loading...