Allinonesecurityv.com
Allinonesecurityv.com is a malicious website for the promotion of the fake anti-spyware program Personal Antivirus. If a PC user reaches this website it means the browser has been hijacked by trojans related to the rogue scam. Once this happens the user will constantly be redirected to Allinonesecurityv.com. The rogue website will produce a scan which looks like a regular Windows explorer window. Allinonesecurityv.com creates the illusion that it is scanning your system, when all it is doing is reporting non-existent files as threats. Eventually the user will be urged to download Personal Antivirus. Do not fall for this website's trickery, and remove Personal Antivirus as soon as possible.
File System Modifications
- The following files were created in the system:
# File Name 1 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Personal Antivirus.lnk 2 %UserProfile%\Application Data\Microsoft\Windows\winlogon.exe 3 %UserProfile%\Application Data\Personal Antivirus 4 %UserProfile%\Application Data\Personal Antivirus\db 5 %UserProfile%\Application Data\Personal Antivirus\db\config.cfg 6 %UserProfile%\Application Data\Personal Antivirus\db\Timeout.inf 7 %UserProfile%\Application Data\Personal Antivirus\db\Urls.inf 8 %UserProfile%\Application Data\Personal Antivirus\settings.ini 9 %UserProfile%\Application Data\Personal Antivirus\uill.ini 10 %UserProfile%\Application Data\Personal Antivirus\unins000.exe 11 %UserProfile%\Application Data\Personal Antivirus\Uninstall Personal Antivirus.lnk 12 %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iGSh.png 13 %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iMSh.png 14 %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iPSh.png 15 %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iv.exe 16 %UserProfile%\Local Settings\Application Data\Microsoft\Windows\log.txt 17 %UserProfile%\Local Settings\Application Data\Microsoft\Windows\pguard.ini 18 %UserProfile%\Local Settings\Application Data\Microsoft\Windows\services.exe 19 c:\Documents and Settings\All Users\Desktop\Personal Antivirus.lnk 20 c:\Documents and Settings\All Users\Start Menu\Programs\Personal Antivirus 21 c:\Documents and Settings\All Users\Start Menu\Programs\Personal Antivirus\Personal Antivirus Home Page.lnk 22 c:\Documents and Settings\All Users\Start Menu\Programs\Personal Antivirus\Personal Antivirus.lnk 23 c:\Documents and Settings\All Users\Start Menu\Programs\Personal Antivirus\Purchase License.lnk 24 c:\Program Files\Personal Antivirus 25 c:\Program Files\Personal Antivirus\activate.ico 26 c:\Program Files\Personal Antivirus\db 27 c:\Program Files\Personal Antivirus\db\DBInfo.ver 28 c:\Program Files\Personal Antivirus\db\ia080614.db 29 c:\Program Files\Personal Antivirus\db\ia080618x.db 30 c:\Program Files\Personal Antivirus\Explorer.ico 31 c:\Program Files\Personal Antivirus\Languages 32 c:\Program Files\Personal Antivirus\Languages\IAEs.lng 33 c:\Program Files\Personal Antivirus\Languages\IAFr.lng 34 c:\Program Files\Personal Antivirus\Languages\IAGer.lng 35 c:\Program Files\Personal Antivirus\Languages\IAIt.lng 36 c:\Program Files\Personal Antivirus\PerAvir.exe 37 c:\Program Files\Personal Antivirus\unins000.dat 38 c:\Program Files\Personal Antivirus\uninstall.ico 39 c:\Program Files\Personal Antivirus\working.log 40 c:\WINDOWS\system32\log.txt 41 PerAvir.exe 42 PersonalAv.exe 43 services.exe 44 winlogon.exe
Registry Modifications
- The following newly produced Registry Values are:
HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "PrS"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Personal Antivirus"HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ITGRDENGINEHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ITGrdEngineHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Personal Antivirus_is1
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.