Home Rogue Websites SecurityScan4You.com

SecurityScan4You.com

Posted: April 15, 2009

SecurityScan4You.com is a scam website dedicated to promoting the rogue anti-spyware remover, System Security 2009. SecurityScan4You.com pretends to scan your PC, discovering numerous "infections" along the way, and sending you security alerts. How sweet.
SecurityScan4You.com pop-ups read as follows:

"http://SecurityScan4You.com says:
Warning!!! Your computer contains various signs of viruses and malware programs presence. Your system requires immediate anti viruses check! System Security will perform a quick and free scanning of your PC for viruses and malicious programs."

And:

"The page at http://SecurityScan4You.com says:
Your computer remains infected by viruses! They can cause data loss and file damages and need to be cured as soon as possible. Return to System Security and download it secure to your PC"

Despite these warnings, if you do not recall how you got to SecurityScan4You.com, then chances are the only spyware you are infected with is SecurityScan4You.com.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %\Documents and Settings%\All Users\Application Data\00308937\00308937.exe
    2 %\Documents and Settings%\All Users\Application Data\00308937\config.udb
    3 %\Documents and Settings%\All Users\Application Data\00308937\pc00308937ins
    4 %UserProfile%\Desktop\System Security 2009.lnk
    5 %UserProfile%\Start Menu\Programs\System Security\System Security 2009 Support.lnk
    6 %UserProfile%\Start Menu\Programs\System Security\System Security 2009.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\Software\00308937HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "00308937"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}SystemSecurity2009

Additional Information on SecurityScan4You.com

  • The following domains were detected:
    # Domain
    1 SecurityScan4You.com
Loading...