Threat Database Rogue Websites Personalfoldertest.com

Personalfoldertest.com

By GoldSparrow in Rogue Websites

Personalfoldertest.com is a browser hijacker promoting the distribution of the rogue anti-spyware application known as Personal Antivirus. Due to affiliated trojans infiltrating the computer via security exploits and modifying the browser settings, web-surfing activities are redirected to the Personalfoldertest.com domain. Once here, the computer is subject to a fake online scan that displays fictitious and sometimes grossly exaggerated infection results, all in order to intimidate the user into purchasing and downloading the fake spyware remover Personal Antivirus.

File System Details

Personalfoldertest.com may create the following file(s):
# File Name Detections
1. %Program Files%\Personal Antivirus\PerAvir.exe
2. %UserProfile%\Local Settings\Application Data\Microsoft\Windows\services.exe
3. %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iv.exe
4. %UserProfile%\Application Data\Personal Antivirus\unins000.exe
5. %UserProfile%\Application Data\Microsoft\Windows\winlogon.exe
6. %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus\Personal Antivirus Home Page.lnk
7. %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Personal Antivirus.lnk
8. %UserProfile%\Application Data\Personal Antivirus\uill.ini
9. %UserProfile%\Application Data\Personal Antivirus\db\config.cfg
10. %UserProfile%\Local Settings\Application Data\Microsoft\Windows\log.txt
11. %Program Files%\Personal Antivirus\activate.ico
12. %Program Files%\Personal Antivirus\uninstall.ico
13. %Program Files%\Personal Antivirus\db\DBInfo.ver
14. %Program Files%\Personal Antivirus\Languages\IAEs.lng
15. %Program Files%\Personal Antivirus\Languages\IAIt.lng
16. %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iMSh.png
17. %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus
18. %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus\Purchase License.lnk
19. %UserProfile%\Application Data\Personal Antivirus\settings.ini
20. %UserProfile%\Application Data\Personal Antivirus\db
21. %UserProfile%\Application Data\Personal Antivirus\db\Urls.inf
22. %Program Files%\Personal Antivirus
23. %Program Files%\Personal Antivirus\unins000.dat
24. %Program Files%\Personal Antivirus\db
25. %Program Files%\Personal Antivirus\db\ia080618x.db
26. %Program Files%\Personal Antivirus\Languages\IAGer.lng
27. %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iGSh.png
28. %Documents and Settings%\All Users\Desktop\Personal Antivirus.lnk
29. %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus\Personal Antivirus.lnk
30. %UserProfile%\Application Data\Personal Antivirus
31. %UserProfile%\Application Data\Personal Antivirus\Uninstall Personal Antivirus.lnk
32. %UserProfile%\Application Data\Personal Antivirus\db\Timeout.inf
33. %UserProfile%\Local Settings\Application Data\Microsoft\Windows\pguard.ini
34. %Program Files%\Personal Antivirus\Explorer.ico
35. %Program Files%\Personal Antivirus\working.log
36. %Program Files%\Personal Antivirus\db\ia080614.db
37. %Program Files%\Personal Antivirus\Languages\IAFr.lng
38. %WINDOWS%\system32\log.txt
39. %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iPSh.png

Registry Details

Personalfoldertest.com may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ITGrdEngine
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ITGRDENGINE
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Personal Antivirus"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Personal Antivirus_is1
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "PrS"

Trending

Most Viewed

Loading...