Srv-scan.us

Srv-scan.us is a browser hijacker sponsoring the rogue anti-spyware program known as System Protector. Due to affiliated trojans infiltrating your system and altering browser settings, you will find your web-surfing activities being diverted to the Srv-scan.us domain, where your computer is subject to a false online scan. This scan reports numerous fictitious infection results in an attempt to scare you into purchasing System Protector.

File System Details

Srv-scan.us may create the following file(s):
# File Name Detections
1. %UserProfile%\Application Data\shellex.dll
2. %UserProfile%\Application Data\lsascs.exe
3. %UserProfile%\Application Data\install.exe
4. %UserProfile%\Application Data\Microsoft\windll32.exe
5. %UserProfile%\Desktop\System Protector.lnk
6. %UserProfile%\Start Menu\Programs\System Protector\System Protector.lnk
7. %UserProfile%\Application Data\SpyProtectorSC_Config.ini
8. %UserProfile%\Start Menu\Programs\System Protector\Support Page.url
9. %WINDOWS%\system32\spyprotector.cpl
10. %UserProfile%\Application Data\SpyProtectorSC_Base_new.dat
11. %UserProfile%\Start Menu\Programs\System Protector\Purchase License.url
12. %Program Files%\System Protector

Registry Details

Srv-scan.us may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\System Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "System Protector"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\System Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\System Protector
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\lsascs.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" => 1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{107A1D63-2EAA-4694-8ABA-EC209C630D83}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\System Protector

Trending

Most Viewed

Loading...