Paladin Antivirus
Paladin Antivirus Description
Paladin Antivirus is a rogue anti-virus application created by the same authors of the rogueware Malware Defense. Paladin Antivirus is distributed by Trojans that can sneak it onto a computer without a user’s knowledge or permission. Once inside a PC, Paladin Antivirus will launch a fake system scan and claim to detect numerous computer threats that can only be removed with its “full” version. Paladin Antivirus often creates a registry entry that will ensure that it is loaded with every system start-up. Paladin Antivirus will also locate a list of legitimate security applications and direct the user to uninstall them. These security applications include: F-Secure, Malwarebytes’ Anti-Malware, Avira AntiVir, NOD32, avast! and more. All scan reports or security alerts displayed by PaladinAntivirus should be ignored.
Type: Rogue Anti-Virus Program
How Can You Detect Paladin Antivirus?
Paladin Antivirus Technical Report
As new Paladin Antivirus details are reported by our customers and findings from our Threat Research Center, we will update this section.
The following Paladin Antivirus files with its MD5s were created in the system:
| File Name | File Size | MD5 |
|---|
| phook.dll | 9216 | d2cf8c85cda2d189ae311073e42af609 |
| pav.exe | 2220032 | d7f99e8f3bd8a91cd76593acd99ffe89 |
| pavext.dll | 37376 | 5585c4da24fcf724c8bc3eede4a4d813 |
| pav.exe | 2342912 | 814cafe042f1fcec320b5a1793f5f622 |
| pavext.dll | 38912 | 3126412023f447ff67644f89aa0e51b7 |
| asr64_ldm.exe | 615424 | b17fbd42afcf742fc4cb5851b9518267 |
Paladin Antivirus has typically the following processes in memory:
- %Program Files%\Paladin Antivirus\phook.dll
- %Program Files%\Paladin Antivirus\pavext.dll
- pavext.dll
- %Program Files%\Paladin Antivirus\pav.exe
- %Program Files%\Paladin Antivirus\uninstall.exe
Paladin Antivirus created the following directories, files, paths:
- %ProgramFiles%\Paladin Antivirus
- %UserProfile%\Start Menu\Programs\Paladin Antivirus
Paladin Antivirus creates the following registry entries:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “Paladin Antivirus”
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Paladin Antivirus
- HKEY_LOCAL_MACHINE\SOFTWARE\Paladin Antivirus
- Paladin Antivirus
Important Article Disclaimer

English 
Deutsch
Español
Français
Portuguese
Paladin Antivirus 












February 21st, 2010 at %I:%M %p
I got alot of trojans and malware errors on my computer and download the paladin virus program.. I can’t find it on my computer and have read that this this a rogue, fake and malware program and have paid for it an can’t find how to e-mail them to get a refund.. can u help
March 4th, 2010 at %I:%M %p
i love the program but can afford the price because in our country we do ot use any of the billing processes