Home Malware Programs Browser Hijackers Scanner.just-protect-pc.info

Scanner.just-protect-pc.info

Posted: February 9, 2010

Scanner.just-protect-pc.info is a browser hijacker designed to perform various corrupt actions related to the malicious sale of the Antivirus rogue software. Scanner.just-protect-pc.info produces bogus material to con computer users into purchasing their rogue software. Do not click on anything related to these parasites and use a reliable anti-spyware program to remove all threats related to Antivirus and Scanner.just-protect-pc.info immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\Microsoft\Internet Explorer\Quick Launch\Antivirus.lnk
    2 %Documents and Settings%\All Users\Desktop\Antivirus.lnk
    3 %Documents and Settings%\All Users\Start Menu\Programs\Antivirus
    4 %Documents and Settings%\All Users\Start Menu\Programs\Antivirus\Antivirus.lnk
    5 %Documents and Settings%\All Users\Start Menu\Programs\Antivirus\Uninstall.lnk
    6 %Program Files%\Antivirus
    7 %Program Files%\Antivirus\Antivirus.exe
    8 %Program Files%\Antivirus\AvBho.dll
    9 %Program Files%\Antivirus\Uninstall.exe
    10 %Program Files%\Antivirus\wscsvc32.exe
    11 %Temp%\winupd64x.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Antivirus.exe"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "wscsvc32.exe"HKEY_LOCAL_MACHINE\SOFTWARE\AntivirusHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9d541c6a-573b-4888-b35e-6816e68c3620}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\AvBho.AvBhoAppHKEY_CLASSES_ROOT\AvBho.AvBhoApp.1HKEY_CLASSES_ROOT\CLSID\{9d541c6a-573b-4888-b35e-6816e68c3620}HKEY_CLASSES_ROOT\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}HKEY_CLASSES_ROOT\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}HKEY_CLASSES_ROOT\TypeLib\{65DA0CE6-30D1-4144-A0B6-59BD01372E26}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Antivirus
Loading...