Home Rogue Websites Allinonesecurityv.com

Allinonesecurityv.com

Posted: November 23, 2009

Allinonesecurityv.com is a malicious website for the promotion of the fake anti-spyware program Personal Antivirus. If a PC user reaches this website it means the browser has been hijacked by trojans related to the rogue scam. Once this happens the user will constantly be redirected to Allinonesecurityv.com. The rogue website will produce a scan which looks like a regular Windows explorer window. Allinonesecurityv.com creates the illusion that it is scanning your system, when all it is doing is reporting non-existent files as threats. Eventually the user will be urged to download Personal Antivirus. Do not fall for this website's trickery, and remove Personal Antivirus as soon as possible.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Personal Antivirus.lnk
    2 %UserProfile%\Application Data\Microsoft\Windows\winlogon.exe
    3 %UserProfile%\Application Data\Personal Antivirus
    4 %UserProfile%\Application Data\Personal Antivirus\db
    5 %UserProfile%\Application Data\Personal Antivirus\db\config.cfg
    6 %UserProfile%\Application Data\Personal Antivirus\db\Timeout.inf
    7 %UserProfile%\Application Data\Personal Antivirus\db\Urls.inf
    8 %UserProfile%\Application Data\Personal Antivirus\settings.ini
    9 %UserProfile%\Application Data\Personal Antivirus\uill.ini
    10 %UserProfile%\Application Data\Personal Antivirus\unins000.exe
    11 %UserProfile%\Application Data\Personal Antivirus\Uninstall Personal Antivirus.lnk
    12 %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iGSh.png
    13 %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iMSh.png
    14 %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iPSh.png
    15 %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iv.exe
    16 %UserProfile%\Local Settings\Application Data\Microsoft\Windows\log.txt
    17 %UserProfile%\Local Settings\Application Data\Microsoft\Windows\pguard.ini
    18 %UserProfile%\Local Settings\Application Data\Microsoft\Windows\services.exe
    19 c:\Documents and Settings\All Users\Desktop\Personal Antivirus.lnk
    20 c:\Documents and Settings\All Users\Start Menu\Programs\Personal Antivirus
    21 c:\Documents and Settings\All Users\Start Menu\Programs\Personal Antivirus\Personal Antivirus Home Page.lnk
    22 c:\Documents and Settings\All Users\Start Menu\Programs\Personal Antivirus\Personal Antivirus.lnk
    23 c:\Documents and Settings\All Users\Start Menu\Programs\Personal Antivirus\Purchase License.lnk
    24 c:\Program Files\Personal Antivirus
    25 c:\Program Files\Personal Antivirus\activate.ico
    26 c:\Program Files\Personal Antivirus\db
    27 c:\Program Files\Personal Antivirus\db\DBInfo.ver
    28 c:\Program Files\Personal Antivirus\db\ia080614.db
    29 c:\Program Files\Personal Antivirus\db\ia080618x.db
    30 c:\Program Files\Personal Antivirus\Explorer.ico
    31 c:\Program Files\Personal Antivirus\Languages
    32 c:\Program Files\Personal Antivirus\Languages\IAEs.lng
    33 c:\Program Files\Personal Antivirus\Languages\IAFr.lng
    34 c:\Program Files\Personal Antivirus\Languages\IAGer.lng
    35 c:\Program Files\Personal Antivirus\Languages\IAIt.lng
    36 c:\Program Files\Personal Antivirus\PerAvir.exe
    37 c:\Program Files\Personal Antivirus\unins000.dat
    38 c:\Program Files\Personal Antivirus\uninstall.ico
    39 c:\Program Files\Personal Antivirus\working.log
    40 c:\WINDOWS\system32\log.txt
    41 PerAvir.exe
    42 PersonalAv.exe
    43 services.exe
    44 winlogon.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "PrS"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Personal Antivirus"HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ITGRDENGINEHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ITGrdEngineHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Personal Antivirus_is1
Loading...