Home Rogue Websites Sys-scan-1.biz

Sys-scan-1.biz

Posted: April 3, 2009

The website for Sys-scan-1.biz is entitled "System Antivirus Scanner", and for good reason. Sys-scan-1.biz looks like a scanner that performs checks on your computer system for infections, and locates an assortment of them. Of course, all of these are fake, as Sys-scan-1.biz is a rogue website pushing the malicious anti-spyware program System Protector.

Usually a Trojan virus becomes deeply embedded in your system via holes and vulnerabilities in your security software, and then alters your browser settings so that you are continuously redirected to the Sys-scan-1.biz webpage. Here is where you receive an onslaught of pop-ups and security alert messages notifying you that your computer is at risk and suggesting you purchase and install System Protector.

Any infections that Sys-scan-1.biz detects are completely fraudulent. This is nothing but a scare tactic used to get you to purchase System Protector, which will do nothing for your computer other than slow down its overall performance and most likely cause system crashes.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Program Files%\System Protector
    2 %UserProfile%\Application Data\install.exe
    3 %UserProfile%\Application Data\lsascs.exe
    4 %UserProfile%\Application Data\Microsoft\windll32.exe
    5 %UserProfile%\Application Data\shellex.dll
    6 %UserProfile%\Application Data\SpyProtectorSC_Base_new.dat
    7 %UserProfile%\Application Data\SpyProtectorSC_Config.ini
    8 %UserProfile%\Desktop\System Protector.lnk
    9 %UserProfile%\Start Menu\Programs\System Protector\Purchase License.url
    10 %UserProfile%\Start Menu\Programs\System Protector\Support Page.url
    11 %UserProfile%\Start Menu\Programs\System Protector\System Protector.lnk
    12 %WINDOWS%\system32\spyprotector.cpl
Loading...