Antiviruspowerfulscanv2.com

Antiviruspowerfulscanv2.com Description

Antiviruspowerfulscanv2.com is a rogue website promoting the fake spyware remover called Personal Antivirus. Affiliated trojans infiltrate the system through security exploits in order to alter browser settings, causing redirection of web-surfing activities to the antiviruspowerfulscanv2.com domain. Here the compromised machine is subject to a false online scan that will typically report fabricated infection threats in order to intimidate the user into purchasing and installing the rogue anti-spyware program Personal Antivirus.

Technical Information

File System Details

Antiviruspowerfulscanv2.com creates the following file(s):
# File Name Detection Count
1 %UserProfile%\Local Settings\Application Data\Microsoft\Windows\services.exe N/A
2 %UserProfile%\Application Data\Personal Antivirus\unins000.exe N/A
3 %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iv.exe N/A
4 %Program Files%\Personal Antivirus\PerAvir.exe N/A
5 %UserProfile%\Application Data\Microsoft\Windows\winlogon.exe N/A
6 %Program Files%\Personal Antivirus\unins000.dat N/A
7 %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus N/A
8 %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus\Purchase License.lnk N/A
9 %UserProfile%\Application Data\Personal Antivirus\settings.ini N/A
10 %UserProfile%\Application Data\Personal Antivirus\db N/A
11 %UserProfile%\Application Data\Personal Antivirus\db\Urls.inf N/A
12 %Program Files%\Personal Antivirus N/A
13 %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iMSh.png N/A
14 %Program Files%\Personal Antivirus\db N/A
15 %Program Files%\Personal Antivirus\db\ia080618x.db N/A
16 %Program Files%\Personal Antivirus\Languages\IAFr.lng N/A
17 %Program Files%\Personal Antivirus\Explorer.ico N/A
18 %Documents and Settings%\All Users\Desktop\Personal Antivirus.lnk N/A
19 %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus\Personal Antivirus.lnk N/A
20 %UserProfile%\Application Data\Personal Antivirus N/A
21 %UserProfile%\Application Data\Personal Antivirus\Uninstall Personal Antivirus.lnk N/A
22 %UserProfile%\Application Data\Personal Antivirus\db\Timeout.inf N/A
23 %UserProfile%\Local Settings\Application Data\Microsoft\Windows\pguard.ini N/A
24 %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iGSh.png N/A
25 %Program Files%\Personal Antivirus\working.log N/A
26 %Program Files%\Personal Antivirus\db\ia080614.db N/A
27 %Program Files%\Personal Antivirus\Languages\IAEs.lng N/A
28 %Program Files%\Personal Antivirus\Languages\IAIt.lng N/A
29 %Program Files%\Personal Antivirus\activate.ico N/A
30 %Program Files%\Personal Antivirus\uninstall.ico N/A
31 %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus\Personal Antivirus Home Page.lnk N/A
32 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Personal Antivirus.lnk N/A
33 %UserProfile%\Application Data\Personal Antivirus\uill.ini N/A
34 %UserProfile%\Application Data\Personal Antivirus\db\config.cfg N/A
35 %UserProfile%\Local Settings\Application Data\Microsoft\Windows\log.txt N/A
36 %WINDOWS%\system32\log.txt N/A
37 %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iPSh.png N/A
38 %Program Files%\Personal Antivirus\db\DBInfo.ver N/A
39 %Program Files%\Personal Antivirus\Languages N/A
40 %Program Files%\Personal Antivirus\Languages\IAGer.lng N/A

Registry Details

Antiviruspowerfulscanv2.com creates the following registry entry or registry entries:
Registry key
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ITGrdEngine
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ITGRDENGINE
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Personal Antivirus"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Personal Antivirus_is1
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "PrS"