Bestscanpc.biz

Bestscanpc.biz Description

Bestscanpc.biz is a browser hijacker promoting the distribution of the rogue anti-spyware application known as System Security 2009. Due to affiliated trojans infiltrating the computer via security exploits and modifying the browser settings, web-surfing activities are redirected to the Bestscanpc.biz domain. Once here, the computer is subject to a fake online scan that displays fictitious and sometimes grossly exaggerated infection results, all in order to intimidate the user into purchasing and downloading the fake spyware remover System Security 2009.

Technical Information

File System Details

Bestscanpc.biz creates the following file(s):
# File Name Detection Count
1 %\Documents and Settings%\All Users\Application Data\00308937\00308937.exe N/A
2 %Program Files%\AdvancedVirusRemover\PAVRM.exe N/A
3 %UserProfile%\Desktop\Advanced Virus Remover.lnk N/A
4 %\Documents and Settings%\All Users\Application Data\00308937\config.udb N/A
5 %UserProfile%\Start Menu\Programs\System Security\System Security 2009.lnk N/A
6 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced Virus Remover.lnk N/A
7 %\Documents and Settings%\All Users\Application Data\00308937\pc00308937ins N/A
8 %UserProfile%\Start Menu\Programs\System Security\System Security 2009 Support.lnk N/A
9 %Program Files%\AdvancedVirusRemover N/A
10 %UserProfile%\Start Menu\Advanced Virus Remover.lnk N/A
11 %UserProfile%\Desktop\System Security 2009.lnk N/A

Registry Details

Bestscanpc.biz creates the following registry entry or registry entries:
Registry key
HKEY_LOCAL_MACHINE\Software\00308937
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\CpMRU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SystemSecurity2009
HKEY_CURRENT_USER\Software\AVR
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "00308937"