Prowebantimalware.com

Prowebantimalware.com Description

Prowebantimalware.com will only be encountered by users that have been infected with Hosts file modifying Trojans. These Trojans ensure that victims are frequently redirected to Prowebantimalware.com. Prowebantimalware.com looks like a user's My Computer interface and once it has been viewed a fake system scan will be conducted on the victim's PC. The scan will reveal exaggerated results of malware infections then the victim will be advised to purchase the fake anti-spyware program, Antivir. Prowebantimalware.com is a malicious website and Antivir will not secure your PC in any way.

Technical Information

File System Details

Prowebantimalware.com creates the following file(s):
# File Name Detection Count
1 %Program Files%\AV\antivir.exe N/A
2 %WINDOWS%\system32\UpdateCheck.dll N/A
3 %Documents and Settings%\All Users\Start Menu\AV N/A
4 %Program Files%\AV N/A
5 %UserProfile%\Desktop\Antivir.lnk N/A
6 %Documents and Settings%\All Users\Start Menu\AV\Uninstall.lnk N/A
7 %Program Files%\Common Files\Uninstall\AV N/A
8 %Program Files%\Common Files\Uninstall\AV\Uninstall.lnk N/A
9 %Documents and Settings%\All Users\Start Menu\AV\Antivir.lnk N/A
10 %Program Files%\Common Files\Uninstall N/A

Registry Details

Prowebantimalware.com creates the following registry entry or registry entries:
Registry key
HKEY_CURRENT_USER\Software\EVAACD
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “AV”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}
HKEY_CLASSES_ROOT\CLSID\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}