Home Rogue Websites Scan.prescansecurepc.com

Scan.prescansecurepc.com

Posted: August 19, 2009

Scan.prescansecurepc.com is a rogue website sponsoring the distribution of the fake spyware remover Smart Protector. To achieve this goal, trojans infiltrate your computer by way of security vulnerabilities and alter the browser settings, causing web-surfing activities to be interrupted and diverted to the Scan.prescansecurepc.com web page. Once here, your PC is subject to a fake online scan that depicts fabricated infection results in order to scare you into purchasing the rogue spyware remover Smart Protector.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Start Menu\Programs\Smart Protector
    2 c:\Documents and Settings\All Users\Application Data\Microsoft\Media Index\Drivers
    3 c:\Program Files\Smart Protector
    4 c:\Program Files\Smart Protector\quarantine

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetHKEY_LOCAL_MACHINE\SOFTWARE\Smart ProtectorHKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96E-E325-11CE-BFC1-08002BE10318}\SHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "smartprotector"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Smart Protector
Loading...