1viruslivescanner.com

1viruslivescanner.com Description

1viruslivescanner.com is a browser hijacker promoting the rogue anti-spyware program called Personal Antivirus. Trojan viruses infiltrate your system via security exploits and modify your browser settings, in order to redirect casual web-surfing activities to the 1viruslivescanner.com domain. Here you are greeted with aggressive advertising schemes and a false online scan, which reports various fictitious infection results. This is used to intimidate you into purchasing the fake spyware remover Personal Antivirus.

Technical Information

File System Details

1viruslivescanner.com creates the following file(s):
# File Name Detection Count
1 %UserProfile%\Local Settings\Application Data\Microsoft\Windows\services.exe N/A
2 %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iv.exe N/A
3 %Program Files%\Personal Antivirus\PerAvir.exe N/A
4 %UserProfile%\Application Data\Microsoft\Windows\winlogon.exe N/A
5 %UserProfile%\Application Data\Personal Antivirus\unins000.exe N/A
6 %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iPSh.png N/A
7 %Documents and Settings%\All Users\Desktop\Personal Antivirus.lnk N/A
8 %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus\Personal Antivirus.lnk N/A
9 %Program Files%\Personal Antivirus\db\DBInfo.ver N/A
10 %Program Files%\Personal Antivirus\Languages N/A
11 %Program Files%\Personal Antivirus\Languages\IAGer.lng N/A
12 %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus\Purchase License.lnk N/A
13 %UserProfile%\Application Data\Personal Antivirus\settings.ini N/A
14 %UserProfile%\Application Data\Personal Antivirus\db N/A
15 %UserProfile%\Application Data\Personal Antivirus\db\Urls.inf N/A
16 %Program Files%\Personal Antivirus\Explorer.ico N/A
17 %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iMSh.png N/A
18 %UserProfile%\Local Settings\Application Data\Microsoft\Windows\pguard.ini N/A
19 %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus\Personal Antivirus Home Page.lnk N/A
20 %Program Files%\Personal Antivirus\db N/A
21 %Program Files%\Personal Antivirus\db\ia080618x.db N/A
22 %Program Files%\Personal Antivirus\Languages\IAFr.lng N/A
23 %WINDOWS%\system32\log.txt N/A
24 %UserProfile%\Application Data\Personal Antivirus N/A
25 %UserProfile%\Application Data\Personal Antivirus\Uninstall Personal Antivirus.lnk N/A
26 %UserProfile%\Application Data\Personal Antivirus\db\Timeout.inf N/A
27 %Program Files%\Personal Antivirus\activate.ico N/A
28 %Program Files%\Personal Antivirus\uninstall.ico N/A
29 %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iGSh.png N/A
30 %UserProfile%\Local Settings\Application Data\Microsoft\Windows\log.txt N/A
31 %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus N/A
32 %Program Files%\Personal Antivirus\working.log N/A
33 %Program Files%\Personal Antivirus\db\ia080614.db N/A
34 %Program Files%\Personal Antivirus\Languages\IAEs.lng N/A
35 %Program Files%\Personal Antivirus\Languages\IAIt.lng N/A
36 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Personal Antivirus.lnk N/A
37 %UserProfile%\Application Data\Personal Antivirus\uill.ini N/A
38 %UserProfile%\Application Data\Personal Antivirus\db\config.cfg N/A
39 %Program Files%\Personal Antivirus N/A
40 %Program Files%\Personal Antivirus\unins000.dat N/A

Registry Details

1viruslivescanner.com creates the following registry entry or registry entries:
RegistryKey
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ITGrdEngine
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ITGRDENGINE
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Personal Antivirus"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Personal Antivirus_is1
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "PrS"