Home Rogue Websites Scan4note.com

Scan4note.com

Posted: May 18, 2009

Scan4note.com is a rogue website sponsoring the fake spyware remover known as Internet Antivirus Pro. In order to achieve this, affiliated trojans infiltrate the system via security holes and alter the browser settings, causing web-surfing activities to be diverted to the Scan4note.com webpage. Here your PC is subject to a free, albeit fake, online scan that reports numerous fabricated and exaggerated infection results. It does this so that you will be scared into purchasing Internet Antivirus Pro.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %APPDATA%\Microsoft\Windows\winlogon.exe
    2 %LOCAL APPDATA%\Microsoft\Internet Explorer\iv.exe
    3 %LOCAL APPDATA%\Microsoft\Windows\services.exe
    4 %Program Files%\Internet Antivirus Pro\iapro.exe
    5 iainstall.exe
    6 iapro.exe
    7 install.exe
    8 InternetAntivirusPro.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Internet Antivirus ProHKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Policies\Explorer\run "iv":HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Run "Internet Antivirus Pro"HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Runonce "3p_udec_ia"
Loading...