Threat Database Rogue Websites Antiviruspowerfulscanv2.com

Antiviruspowerfulscanv2.com

Por Domesticus em Rogue Websites

O Ativiruspowerfulscanv2.com é um site nocivo, que promove um falso removedor de spyware chamado Personal Antivirus. Trojans a ele afiliados se infiltram no sistema, através de falhas de segurança, a fim de alterar as configurações do navegador, fazendo o redirecionamento das atividades de navegação para o domínio do antiviruspowerfulscanv2.com. Aqui a máquina comprometida estará sujeita a uma falsa varredura, que normalmente exibe resultados fabricados de ameaças de infecção, a fim de intimidar o usuário e faze-lo adquirir e instalar o anti-spyware nocivo do Personal Antivirus.

Detalhes Sobre os Arquivos do Sistema

Antiviruspowerfulscanv2.com pode criar o(s) seguinte(s) arquivo(s):
# Nome do arquivo Detecções
1. %UserProfile%\Local Settings\Application Data\Microsoft\Windows\services.exe
2. %UserProfile%\Application Data\Personal Antivirus\unins000.exe
3. %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iv.exe
4. %Program Files%\Personal Antivirus\PerAvir.exe
5. %UserProfile%\Application Data\Microsoft\Windows\winlogon.exe
6. %Program Files%\Personal Antivirus\unins000.dat
7. %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus
8. %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus\Purchase License.lnk
9. %UserProfile%\Application Data\Personal Antivirus\settings.ini
10. %UserProfile%\Application Data\Personal Antivirus\db
11. %UserProfile%\Application Data\Personal Antivirus\db\Urls.inf
12. %Program Files%\Personal Antivirus
13. %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iMSh.png
14. %Program Files%\Personal Antivirus\db
15. %Program Files%\Personal Antivirus\db\ia080618x.db
16. %Program Files%\Personal Antivirus\Languages\IAFr.lng
17. %Program Files%\Personal Antivirus\Explorer.ico
18. %Documents and Settings%\All Users\Desktop\Personal Antivirus.lnk
19. %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus\Personal Antivirus.lnk
20. %UserProfile%\Application Data\Personal Antivirus
21. %UserProfile%\Application Data\Personal Antivirus\Uninstall Personal Antivirus.lnk
22. %UserProfile%\Application Data\Personal Antivirus\db\Timeout.inf
23. %UserProfile%\Local Settings\Application Data\Microsoft\Windows\pguard.ini
24. %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iGSh.png
25. %Program Files%\Personal Antivirus\working.log
26. %Program Files%\Personal Antivirus\db\ia080614.db
27. %Program Files%\Personal Antivirus\Languages\IAEs.lng
28. %Program Files%\Personal Antivirus\Languages\IAIt.lng
29. %Program Files%\Personal Antivirus\activate.ico
30. %Program Files%\Personal Antivirus\uninstall.ico
31. %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus\Personal Antivirus Home Page.lnk
32. %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Personal Antivirus.lnk
33. %UserProfile%\Application Data\Personal Antivirus\uill.ini
34. %UserProfile%\Application Data\Personal Antivirus\db\config.cfg
35. %UserProfile%\Local Settings\Application Data\Microsoft\Windows\log.txt
36. %WINDOWS%\system32\log.txt
37. %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iPSh.png
38. %Program Files%\Personal Antivirus\db\DBInfo.ver
39. %Program Files%\Personal Antivirus\Languages
40. %Program Files%\Personal Antivirus\Languages\IAGer.lng

Detalhes sobre o Registro

Antiviruspowerfulscanv2.com pode criar a seguinte entrada de registro ou entradas de registro:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ITGrdEngine
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ITGRDENGINE
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Personal Antivirus"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Personal Antivirus_is1
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "PrS"

Tendendo

Mais visto

Carregando...