Home Malware Programs Browser Hijackers ScanBasic.com

ScanBasic.com

Posted: November 11, 2011

ScanBasic.com Screenshot 1Although ScanBasic.com claims to have a legitimate privacy policy and other characteristics that are associated with reputable websites, under the surface of ScanBasic.com's design lies an old search engine scam that's purposed to redirect you to advertisement websites. Its search engine interface believes ScanBasic.com's real functions, which aren't capable of sorting out irrelevant websites or websites that might be dangerous to your computer – rather than doing this, ScanBasic.com directs you solely to sites that return profit to ScanBasic.com. SpywareRemove.com malware research team has also connected ScanBasic.com to other types of preexisting search engine scams and, in particular, to browser hijackers that can force your web browser to ScanBasic.com no matter what site you're trying to view. However, minimal exposure to ScanBasic.com and usage of a good anti-malware product to remove any browser hijacker infections will allow your PC to recovery back to perfect health.

All the Basic and Unpleasant Facts About ScanBasic.com

Despite its look and feel as a search engine site, ScanBasic.com doesn't offer any genuine search engine features and has no way of connecting the dots from your search queries over to relevant websites. You can expect that any links that ScanBasic.com offers you will always present valueless or even malicious content instead of content that's related to your search terms. Accidental exposure to malicious scripts and other types of harmful content from ScanBasic.com can be reduced by keeping an up-to-date web browser with high security setting levels (particularly for the usage of scripts, such as Java and Flash).

ScanBasic.com can also be considered a clone of other fake search engine websites that share its template and scam methodology, such as QuestDNS.com, QueryExplorer.com, Searchqu.com, Ziniky.com, Zumie.com and BarQuery.com. Browser-hijacking Trojans may redirect you to any of these sites or other clones of ScanBasic.com in addition to ScanBasic.com itself, and you should react to all of them with equivalent safety measures.

Freeing Your Browser from the Burden of ScanBasic.com

The most likely way of contact with ScanBasic.com is through a browser hijacker that redirects your browser to ScanBasic.com, if you try to use another site (especially including other search engines). Other symptoms of infection by a browser hijacker for ScanBasic.com can include:

  • Browser window pop-ups.
  • Sluggish browser performance.
  • Having ScanBasic.com set to be your default homepage or 'new page' website.
  • Being unable to change your browser's settings.

Removing a browser-hijacking Trojan that's affiliated with ScanBasic.com is best accomplished with an up-to-date anti-malware scanner, and SpywareRemove.com malware experts note that changing or deleting your web browser will only treat the symptom of the Trojan, while leaving the actual Trojan intact. However, long-term harm from browser hijackers for ScanBasic.com should be a rare occurrence, as long as the guilty infection is removed with proper software and procedures.

If you experience the Trojan for ScanBasic.com blocking your ability to access a necessary security program, you can rename the program file to a generic file name (like 'explorer.exe') or reboot in Safe Mode to duck under the browser hijacker's blacklist.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%AppData%Scanbasicdtx.ini File name: %AppData%Scanbasicdtx.ini
Mime Type: unknown/ini
%AppData%Scanbasiccouponsmerchants.xml File name: %AppData%Scanbasiccouponsmerchants.xml
Mime Type: unknown/xml
%AppData%Scanbasiccouponscategories.xml File name: %AppData%Scanbasiccouponscategories.xml
Mime Type: unknown/xml
%AppData%Scanbasiccouponsmerchants2.xml File name: %AppData%Scanbasiccouponsmerchants2.xml
Mime Type: unknown/xml
%AppData%Scanbasicpreferences.dat File name: %AppData%Scanbasicpreferences.dat
File type: Data file
Mime Type: unknown/dat
%AppData%Scanbasicguid.dat File name: %AppData%Scanbasicguid.dat
File type: Data file
Mime Type: unknown/dat
%AppData%Scanbasiclog.txt File name: %AppData%Scanbasiclog.txt
Mime Type: unknown/txt
%AppData%Scanbasicversion.xml File name: %AppData%Scanbasicversion.xml
Mime Type: unknown/xml
%Temp%Scanbasic-manifest.xml File name: %Temp%Scanbasic-manifest.xml
Mime Type: unknown/xml
%AppData%Scanbasicstat.log File name: %AppData%Scanbasicstat.log
Mime Type: unknown/log
%AppData%Scanbasicstats.dat File name: %AppData%Scanbasicstats.dat
File type: Data file
Mime Type: unknown/dat
%AppData%ScanbasicuninstallIE.dat File name: %AppData%ScanbasicuninstallIE.dat
File type: Data file
Mime Type: unknown/dat
%AppData%ScanbasicuninstallStatIE.dat File name: %AppData%ScanbasicuninstallStatIE.dat
File type: Data file
Mime Type: unknown/dat

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINESOFTWAREClassesBasicExplorerIEHelper.DNSGuard.1HKEY_LOCAL_MACHINESOFTWAREClassesBasicExplorerIEHelper.DNSGuardHKEY_LOCAL_MACHINESOFTWAREClassesBasicExplorerIEHelper.DNSGuardCLSIDHKEY_LOCAL_MACHINESOFTWAREClassesBasicExplorerIEHelper.DNSGuardCurVerHKEY_LOCAL_MACHINESOFTWAREClassesCLSID{A40DC6C5-79D0-4ca8-A185-8FF989AF1115} "UrlHelper Class"HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}ProgID "BasicExplorerIEHelper.UrlHelper.1"HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{99079a25-328f-4bd4-be04-00955acaa0a7} " BasicExplorer BasicExplorer Toolbar"HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar ?BasicExplorer Toolbar?HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}VersionIndependentProgID "BasicExplorerIEHelper.UrlHelper"HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{99079a25-328f-4bd4-be04-00955acaa0a7}InprocServer32 "C:PROGRA~1WINDOW~4ToolBarBasicExplorerdtx.dll"HKEY_LOCAL_MACHINESOFTWAREClassesCLSID{99079a25-328f-4bd4-be04-00955acaa0a7} "BasicExplorer Toolbar"
Loading...