Home Rogue Websites Scanner.av-best.info

Scanner.av-best.info

Posted: March 30, 2009

Scanner.av-best.info is a malicious site that pretends to be able to scan your computer for parasites. Scanner.av-best.info is believed to be related to Virus Doctor and most likely may have been created by the same group of hackers that developed Virus Doctor.

Scanner.av-best.info may appear to be a normal security site but it is designed to promote fake anti-spyware applications that could seriously damage your computer. Scanner.av-best.info should never be visited for any reason. If your default home page has been hijacked or changed, without your knowledge, to Scanner.av-best.info, you may want to scan your system with a reliable anti-spyware program to quickly detect the presence of Scanner.av-best.info and VirusDoctor files.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Virus Doctor.lnk
    2 %UserProfile%\Application Data\Virus Doctor
    3 %UserProfile%\Application Data\Virus Doctor\settings.ini
    4 %UserProfile%\Application Data\Virus Doctor\uill.ini
    5 %UserProfile%\Desktop\Virus Doctor.lnk
    6 %UserProfile%\Start Menu\Programs\Virus Doctor.lnk
    7 %UserProfile%\Start Menu\Virus Doctor.lnk
    8 c:\Documents and Settings\All Users\Application Data\927e
    9 c:\Documents and Settings\All Users\Application Data\927e\Languages
    10 c:\Documents and Settings\All Users\Application Data\927e\Languages\VDDe.lng
    11 c:\Documents and Settings\All Users\Application Data\927e\Languages\VDFr.lng
    12 c:\Documents and Settings\All Users\Application Data\927e\Languages\VDIt.lng
    13 c:\Documents and Settings\All Users\Application Data\927e\mozcrt19.dll
    14 c:\Documents and Settings\All Users\Application Data\927e\sqlite3.dll
    15 c:\Documents and Settings\All Users\Application Data\927e\System Data Configuration
    16 c:\Documents and Settings\All Users\Application Data\927e\System Data Configuration\DBInfo.ver
    17 c:\Documents and Settings\All Users\Application Data\927e\System Data Configuration\vd952342.bd
    18 c:\Documents and Settings\All Users\Application Data\927e\unins000.dat
    19 c:\Documents and Settings\All Users\Application Data\927e\unins000.exe
    20 c:\Documents and Settings\All Users\Application Data\927e\VDoca582.exe
    21 c:\Documents and Settings\All Users\Application Data\System Data Configuration
    22 c:\Documents and Settings\All Users\Application Data\System Data Configuration\config.cfg
    23 c:\Documents and Settings\All Users\Application Data\System Data Configuration\DB.ini
    24 c:\Documents and Settings\All Users\Application Data\System Data Configuration\fsvd6398.db
    25 VDoctor.exe
    26 Virus Doctor.lnk
    27 VirusDoctor[1].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Virus Doctor"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "URVDoc[]"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Virus Doctor_is1
Loading...