Home Rogue Websites Way4scan.info

Way4scan.info

Posted: May 4, 2009

Way4scan.info is an aggressive browser hijacker sponsoring the fake spyware remover known as Internet Antivirus Pro. Through backdoor trojans that infiltrate your system and alter your browser settings, Way4scan.info is typically redirected to during ordinary web-surfing activities. Once there, your computer is subject to a fraudulent online scan that reports various fabricated infections, all in order to frighten you into purchasing Internet Antivirus Pro.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %APPDATA%\Microsoft\Windows\winlogon.exe
    2 %LOCAL APPDATA%\Microsoft\Internet Explorer\iv.exe
    3 %LOCAL APPDATA%\Microsoft\Windows\services.exe
    4 %Program Files%\Internet Antivirus Pro\iapro.exe
    5 iainstall.exe
    6 iapro.exe
    7 install.exe
    8 InternetAntivirusPro.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Internet Antivirus ProHKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Policies\Explorer\run "iv":HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Run "Internet Antivirus Pro"HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Runonce "3p_udec_ia"
Loading...