ScanBasic.com

By JubileeX in Browser Hijackers

ScanBasic.com Image

ScanBasic.com is a rogue search engine. Rather than functioning as a regular search engine, that is, answering an online search with a list of websites that match the user's search, ScanBasic.com will always list booby-trapped websites that point to advertisements (regardless of the computer user's search). If the fake search engine ScanBasic.com limited itself to this practice, ScanBasic.com would be quite harmless; computer users would simply be able to avoid visiting ScanBasic.com. However, ScanBasic.com works together with a browser hijacker, in order to force its victims to visit its malicious website repeatedly. This is why ESG security researchers consider that ScanBasic.com is a threat to a computer system's integrity. ScanBasic.com is similar to other bogus sites such as BarQuery.com, QueryExplorer.com, QuestDNS.com, Wonderfulserchsystem.com, Nailingsearchsystem.com, Uniquesearchsystem.com.

 
While the ScanBasic.com website in itself is relatively harmless, the vast majority of its visitors are infected with a dangerous Trojan, which hijacks their Internet browser. It is also worth mentioning that most of ScanBasic.com's results lead to known attack websites, web pages associated with known online scams or websites promoting illegal or fraudulent products. Because of this, ESG malware analysts strongly recommend scanning your computer system in the event of having visited ScanBasic.com, either voluntarily or through the effects of a browser hijacker. In either case, it is almost certain that your computer system has become exposed to a variety of dangerous malware infections.
 

How Criminals Profit from Websites Such as ScanBasic.com

Most online revenue comes from the same sources: advertisements and affiliate marketing. This means that the foremost consideration behind most profitable websites is to make sure that you attract a wide audience and that you find ways to keep them engaged in your website's content. Lots of people visiting your website mean lots of people clicking on your advertisements, viewing your advertisements, and following your affiliate marketing links. The legitimate way of generating revenue from a website is by creating interesting and useful content which will attract visitors and keep them engaged. However, in 2011 there has been a surge of the fake search engine scam, a variety of rogue websites (such as ScanBasic.com) associated with dangerous browser hijackers. Instead of providing valuable content, websites such as ScanBasic.com simply use Trojans and other malware threats, in other to force their victims to visit ScanBasic.com repeatedly, thus generating online traffic and a stream of revenue. This practice is illegal and is often associated with dangerous content. There is a reason why these websites advertise themselves with the aid of malicious search engines like ScanBasic.com; they have usually been blocked from legitimate search engines, due to their unsafe content.

File System Details

ScanBasic.com may create the following file(s):
# File Name Detections
1. %AppData%Scanbasiccouponsmerchants.xml
2. %AppData%Scanbasicguid.dat
3. %Temp%Scanbasic-manifest.xml
4. %AppData%ScanbasicuninstallIE.dat
5. %AppData%Scanbasiccouponscategories.xml
6. %AppData%Scanbasicpreferences.dat
7. %AppData%Scanbasicversion.xml
8. %AppData%Scanbasicstats.dat
9. %AppData%Scanbasicdtx.ini
10. %AppData%Scanbasiccouponsmerchants2.xml
11. %AppData%Scanbasiclog.txt
12. %AppData%Scanbasicstat.log
13. %AppData%ScanbasicuninstallStatIE.dat

Registry Details

ScanBasic.com may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}VersionIndependentProgID "BasicExplorerIEHelper.UrlHelper"
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}ProgID "BasicExplorerIEHelper.UrlHelper.1"
HKEY_LOCAL_MACHINESOFTWAREClassesBasicExplorerIEHelper.DNSGuardCLSID
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{99079a25-328f-4bd4-be04-00955acaa0a7}InprocServer32 "C:PROGRA~1WINDOW~4ToolBarBasicExplorerdtx.dll"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{99079a25-328f-4bd4-be04-00955acaa0a7} " BasicExplorer BasicExplorer Toolbar"
HKEY_LOCAL_MACHINESOFTWAREClassesBasicExplorerIEHelper.DNSGuardCurVer
HKEY_LOCAL_MACHINESOFTWAREClassesBasicExplorerIEHelper.DNSGuard.1
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{99079a25-328f-4bd4-be04-00955acaa0a7} "BasicExplorer Toolbar"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar ?BasicExplorer Toolbar?
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{A40DC6C5-79D0-4ca8-A185-8FF989AF1115} "UrlHelper Class"
HKEY_LOCAL_MACHINESOFTWAREClassesBasicExplorerIEHelper.DNSGuard

Trending

Most Viewed

Loading...