Home Malware Programs Browser Hijackers Scanner.av2-site.info

Scanner.av2-site.info

Posted: April 5, 2010

Scanner.av2-site.info is a browser hijacker that is known to promote and sell the rogue anti-spyware application called Antivirus. Scanner.av2-site.info may appear as a legitimate computer scanner but it is not. Once visited, Scanner.av2-site.info will attempt to scan your computer only to return several bogus parasite results in addition to displaying misleading warning messages. Scanner.av2-site.info should be avoided at all costs.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\Microsoft\Internet Explorer\Quick Launch\Antivirus.lnk
    2 %Documents and Settings%\All Users\Desktop\Antivirus.lnk
    3 %Documents and Settings%\All Users\Start Menu\Programs\Antivirus
    4 %Documents and Settings%\All Users\Start Menu\Programs\Antivirus\Antivirus.lnk
    5 %Documents and Settings%\All Users\Start Menu\Programs\Antivirus\Uninstall.lnk
    6 %Program Files%\Antivirus
    7 %Program Files%\Antivirus\Antivirus.exe
    8 %Program Files%\Antivirus\AvBho.dll
    9 %Program Files%\Antivirus\Uninstall.exe
    10 %Program Files%\Antivirus\wscsvc32.exe
    11 %Temp%\winupd64x.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Antivirus.exe"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "wscsvc32.exe"HKEY_LOCAL_MACHINE\SOFTWARE\AntivirusHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9d541c6a-573b-4888-b35e-6816e68c3620}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\AvBho.AvBhoAppHKEY_CLASSES_ROOT\AvBho.AvBhoApp.1HKEY_CLASSES_ROOT\CLSID\{9d541c6a-573b-4888-b35e-6816e68c3620}HKEY_CLASSES_ROOT\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}HKEY_CLASSES_ROOT\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}HKEY_CLASSES_ROOT\TypeLib\{65DA0CE6-30D1-4144-A0B6-59BD01372E26}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Antivirus
Loading...