Home Rogue Websites Scan5new.com

Scan5new.com

Posted: January 12, 2009

Scan5new.com is a rogue website and browser hijacker that promotes the fraudulent Internet Antivirus Pro program. Scan5new.com may change your Internet Explorer settings, redirect your Web searches and change your default home page.

When Scan5new.com appears as your default homepage, it means that there's the presence of a trojan in your computer. The trojan will display fake security alerts claiming that your computer is infected. The sole purpose of these fake security alerts is to trick or scare you into purchasing the rogue Internet Antivirus Pro program. Scan5new.com is not to be trusted. It is recommended that you remove Scan5new.com and the trojan files associated with it immediately as to prevent additional harm to your computer.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\IA\InternetAntivirusPro.exe
    2 %ProgramFiles%\Internet Antivirus Pro\activate.ico
    3 %ProgramFiles%\Internet Antivirus Pro\cookies.log\
    4 %ProgramFiles%\Internet Antivirus Pro\db\config.cfg
    5 %ProgramFiles%\Internet Antivirus Pro\db\DBInfo.ver
    6 %ProgramFiles%\Internet Antivirus Pro\db\ia080614.db
    7 %ProgramFiles%\Internet Antivirus Pro\Explorer.ico
    8 %ProgramFiles%\Internet Antivirus Pro\IAUpdater.exe
    9 %ProgramFiles%\Internet Antivirus Pro\IAvir.exe
    10 %ProgramFiles%\Internet Antivirus Pro\Scanner.log
    11 %ProgramFiles%\Internet Antivirus Pro\unins000.dat
    12 %ProgramFiles%\Internet Antivirus Pro\uninstall.ico
    13 %ProgramFiles%\Internet Antivirus Pro\working.log
    14 ska.dll
    15 ska.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\IAVPHKEY_CURRENT_USER\Software\InternetAntivirusPro2008HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Internet AntivirusPro2008"HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\.keyHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "InternetAntivirusPro2008"
Loading...