|
|
I just want to seek information about Obama and Sarkozy checking butt in G8 meeting. Well, that’s a hot story. I search using this term:
Obama Sarkozy Checking butt
And I land to this page
See what’s in the box?. If you click them, you’ll land to Antivirusfolderscannerv5.com. They’ll scan and give you a fake result:
Fake Scanner Screenshot:

automatically, you’ll download a file, which, maybe will install automatically. Knowing this matter, I kill my internet explorer abruptly.
What they Do?
It is one of the latest malicious sites that is offering to download and purchase a full version of a fake spyware program Personal Antivirus. People are usually redirected to this site from other malicious websites or trojans. Therefore, if you have seen this site you should run a full computer scan and check your system. As it might be infected. Once at the Antivirusfolderscanner.com you will find a well put up website and a scanner running through your computer files. Obviously, it will find a number of infections, viruses, trojans, malware, adware and spyware on your computer and will ask you to purchase a full Personal Antivirus version. Actually, neither the scanner nor the Personal Antivirus is trustworthy. These are both malicious programs, not worth a penny. They find files that even do not exist, they say some files are infected even if they are not and they never find the files that are really infected. So, it is just a waste of money. Moreover, Personal Antivirus slows downs computer and pops up an annoying message that constantly asks user to purchase the full version. Do not do this.
Manual removal of Antivirusfolderscanner.com hijacker and attendant malware is feasible if you have sufficient expertise in dealing with program files, system processes, .dll files and registry entries.
FILES THEY DROPS
The associated files to be deleted are listed below:
- %Documents and Settings%\All Users\Desktop\Personal Antivirus.lnk
- %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus
- %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus\Personal Antivirus Home Page.lnk
- %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus\Personal Antivirus.lnk
- %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus\Purchase License.lnk
- %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Personal Antivirus.lnk
- %UserProfile%\Application Data\Personal Antivirus
- %UserProfile%\Application Data\Personal Antivirus\settings.ini
- %UserProfile%\Application Data\Personal Antivirus\uill.ini
- %UserProfile%\Application Data\Personal Antivirus\unins000.exe
- %UserProfile%\Application Data\Personal Antivirus\Uninstall Personal Antivirus.lnk
- %UserProfile%\Application Data\Personal Antivirus\db
- %UserProfile%\Application Data\Personal Antivirus\db\config.cfg
- %UserProfile%\Application Data\Personal Antivirus\db\Timeout.inf
- %UserProfile%\Application Data\Personal Antivirus\db\Urls.inf
- %UserProfile%\Local Settings\Application Data\Microsoft\Windows\log.txt
- %UserProfile%\Local Settings\Application Data\Microsoft\Windows\pguard.ini
- %UserProfile%\Local Settings\Application Data\Microsoft\Windows\services.exe
- %Program Files%\Personal Antivirus
- %Program Files%\Personal Antivirus\activate.ico
- %Program Files%\Personal Antivirus\Explorer.ico
- %Program Files%\Personal Antivirus\PerAvir.exe
- %Program Files%\Personal Antivirus\unins000.dat
- %Program Files%\Personal Antivirus\uninstall.ico
- %Program Files%\Personal Antivirus\working.log
- %Program Files%\Personal Antivirus\db
- %Program Files%\Personal Antivirus\db\DBInfo.ver
- %Program Files%\Personal Antivirus\db\ia080614.db
- %Program Files%\Personal Antivirus\db\ia080618x.db
- %Program Files%\Personal Antivirus\Languages
- %Program Files%\Personal Antivirus\Languages\IAEs.lng
- %Program Files%\Personal Antivirus\Languages\IAFr.lng
- %Program Files%\Personal Antivirus\Languages\IAGer.lng
- %Program Files%\Personal Antivirus\Languages\IAIt.lng
- %WINDOWS%\system32\log.txt
- %UserProfile%\Application Data\Microsoft\Windows\winlogon.exe
- %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iGSh.png
- %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iMSh.png
- %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iPSh.png
- %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iv.exe
- %UserProfile%\Local Settings\Application Data\Microsoft\Windows\log.txt
- %UserProfile%\Local Settings\Application Data\Microsoft\Windows\pguard.ini
- %UserProfile%\Local Settings\Application Data\Microsoft\Windows\services.exe
The related registry entries to be removed are as follows:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Personal Antivirus_is1
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ITGRDENGINE
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ITGrdEngine
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer “PrS”
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Personal Antivirus”
Please, be aware that manual removal of Antivirusfolderscanner.com hijacker is a cumbersome procedure and does not ensure complete deletion of the malware, due to the fact that some files might be hidden or may automatically reanimate themselves afterwards. Moreover, manual interference of this kind may cause damage to the system. That’s why we strongly recommend automatic removal of Antivirusfolderscanner.com hijacker, which will save your time and enable avoiding any system malfunctions and guarantee the needed result.
To delete it, you can use PC Tools.
Popularity: 2% [?]
| Further reading here... |
Leave a Reply
Don’t Miss a Thing, Subscribe Here
My Stats
Promote Your Site Here
My Alexa Rank
Chat with Me







