Threat Database Rogue Websites Proantivirusscanv3.com

Proantivirusscanv3.com

By Domesticus in Rogue Websites

Proantivirusscanv3.com is a browser hijacker promoting the rogue anti-spyware application known as Personal Antivirus. Due to trojans infiltrating a computer system via security exploits and modifying the browser settings, web-surfing activities are continously redirected to the Proantivirusscanv3.com domain. Here the system is subject to a fake online scan, which results in either fictitious or greatly exaggerated infection results, all used in order to trick the user into purchasing the Personal Antivirus fake spyware remover software.

File System Details

Proantivirusscanv3.com may create the following file(s):
# File Name Detections
1. %Program Files%\Personal Antivirus\PerAvir.exe
2. %UserProfile%\Local Settings\Application Data\Microsoft\Windows\services.exe
3. %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iv.exe
4. %UserProfile%\Application Data\Personal Antivirus\unins000.exe
5. %UserProfile%\Application Data\Microsoft\Windows\winlogon.exe
6. %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus\Personal Antivirus Home Page.lnk
7. %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Personal Antivirus.lnk
8. %UserProfile%\Application Data\Personal Antivirus\uill.ini
9. %UserProfile%\Application Data\Personal Antivirus\db\config.cfg
10. %UserProfile%\Local Settings\Application Data\Microsoft\Windows\log.txt
11. %Program Files%\Personal Antivirus\activate.ico
12. %Program Files%\Personal Antivirus\uninstall.ico
13. %Program Files%\Personal Antivirus\db\DBInfo.ver
14. %Program Files%\Personal Antivirus\Languages
15. %Program Files%\Personal Antivirus\Languages\IAGer.lng
16. %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iGSh.png
17. %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus
18. %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus\Purchase License.lnk
19. %UserProfile%\Application Data\Personal Antivirus\settings.ini
20. %UserProfile%\Application Data\Personal Antivirus\db
21. %UserProfile%\Application Data\Personal Antivirus\db\Urls.inf
22. %Program Files%\Personal Antivirus
23. %Program Files%\Personal Antivirus\unins000.dat
24. %Program Files%\Personal Antivirus\db
25. %Program Files%\Personal Antivirus\db\ia080618x.db
26. %Program Files%\Personal Antivirus\Languages\IAFr.lng
27. %WINDOWS%\system32\log.txt
28. %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iPSh.png
29. %Documents and Settings%\All Users\Desktop\Personal Antivirus.lnk
30. %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus\Personal Antivirus.lnk
31. %UserProfile%\Application Data\Personal Antivirus
32. %UserProfile%\Application Data\Personal Antivirus\Uninstall Personal Antivirus.lnk
33. %UserProfile%\Application Data\Personal Antivirus\db\Timeout.inf
34. %UserProfile%\Local Settings\Application Data\Microsoft\Windows\pguard.ini
35. %Program Files%\Personal Antivirus\Explorer.ico
36. %Program Files%\Personal Antivirus\working.log
37. %Program Files%\Personal Antivirus\db\ia080614.db
38. %Program Files%\Personal Antivirus\Languages\IAEs.lng
39. %Program Files%\Personal Antivirus\Languages\IAIt.lng
40. %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iMSh.png

Registry Details

Proantivirusscanv3.com may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ITGrdEngine
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ITGRDENGINE
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Personal Antivirus"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Personal Antivirus_is1
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "PrS"

Trending

Most Viewed

Loading...