Home Rogue Websites Scanjust6.info

Scanjust6.info

Posted: April 21, 2009

Scanjust6.info is a dangerous rogue website that hijacks your web browser by exploiting backdoor trojans that secretly infiltrate your PC and modify your browser settings, all in order to redirect your web surfing activities to the Scanjust6.info domain. Here you are subjected to a fake online scan that reports numerous counterfeit infections, all in order to frighten you into purchasing the rogue anti-spyware application called Internet Antivirus Pro.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %APPDATA%\Microsoft\Windows\winlogon.exe
    2 %LOCAL APPDATA%\Microsoft\Internet Explorer\iv.exe
    3 %LOCAL APPDATA%\Microsoft\Windows\services.exe
    4 %Program Files%\Internet Antivirus Pro\iapro.exe
    5 iainstall.exe
    6 iapro.exe
    7 install.exe
    8 InternetAntivirusPro.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Internet Antivirus ProHKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Policies\Explorer\run "iv":HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Run "Internet Antivirus Pro"HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Runonce "3p_udec_ia"
Loading...