FrEn

Envoyer Imprimer PDF

Free malware removal tool to remove Paladin Antivirus

Écrit par Administrator  |  Samedi, 27 Février 2010 14:46
AddThis Social Bookmark Button
There are no translations available.

Paladin Antivirus is a rogue Antispyware, a scareware, it's a malware that pretends to be an Antivirus. It is a wolf in sheep's clothing. It conducts a fake scan of your system; you are warned by a fake alarm that there are more malwares on your system. It’s true indeed, there is really a malware in your system but I think the only malware on your system is Paladin Antivirus. It invites you to purchase a license to remove malwares, do not, it's a scam, you need a license for a malware? This so-called Antivirus tries to scam you. Uninstall Paladin Antivirus immediately from your system using this free removal tool for Paladin Antivirus.

Paladin Antivirus

To remove Paladin Antivirus (Uninstall Paladin Antivirus)

  • Download this free removal tool for Paladin Antivirus
  • Extract it
  • Launch
  • Click on the delete button

Paladin Antivirus will be removed from your system in 10s. Restart your computer when it’s finished.

Processes :

  • pav.exe

Files :

  • %AppData%\Microsoft\Internet Explorer\Quick Launch\Paladin Antivirus.lnk
  • %Desktop%\Paladin Antivirus Support.lnk
  • %Desktop%\Paladin Antivirus.lnk
  • %StartMenu%\Programs\Paladin Antivirus
  • %StartMenu%\Programs\Paladin Antivirus\Paladin Antivirus Support.lnk
  • %StartMenu%\Programs\Paladin Antivirus\Paladin Antivirus.lnk
  • %StartMenu%\Programs\Paladin Antivirus\Uninstall Paladin Antivirus.lnk
  • %System%\wbem\Performance\WmiApRpl_new.ini
  • %ProgramFiles%\Paladin Antivirus
  • %ProgramFiles%\Paladin Antivirus\help.ico
  • %ProgramFiles%\Paladin Antivirus\pav.db
  • %ProgramFiles%\Paladin Antivirus\pav.exe
  • %ProgramFiles%\Paladin Antivirus\pavext.dll
  • %ProgramFiles%\Paladin Antivirus\phook.dll
  • %ProgramFiles%\Paladin Antivirus\uninstall.exe
  • %Temp%\4otjesjty.mof
  • %Temp%\pav.dat
  • %Temp%\pavr.dat

Registry

Registry keys created

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Paladin Antivirus
  • HKEY_LOCAL_MACHINE\SOFTWARE\Paladin Antivirus
  • HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_LOCAL_MACHINE\SOFTWARE\Paladin Antivirus
  • HKEY_CURRENT_USER\Software\Microsoft\Multimedia\Video For Windows
  • HKEY_CURRENT_USER\Software\Microsoft\Multimedia\Video For Windows\MCIAVI

Registry values created

  • HKEY_LOCAL_MACHINE\SOFTWARE\Paladin Antivirus
    • Settings_0 = 0x00000001
    • SecStatus_3 = 0x00000001
    • SecStatus_4 = 0x00000001
    • SecStatus_5 = 0x00000001
    • FD = 0x00000000
    • GUID = "691210486911968069118321"
    • Data = ":1920:2040:2160:2280:2400:2520:2640:2880:3000:3120:"
    • swver = "3.0"
    • dbver = "1.1"
    • dbsigns = "62577"
    • dbverf = "1.1"
    • dbsignsf = "62577"
    • InfectedFiles = "%System%\slbcsp.dll,%System%\themeui.dll,%System%\w32time.dll,%System%
    • \WPWIZDLL.DLL,%System%\Wbem\subscrpt.mof,%System%\Drivers\cinemst2.sys,%System%\Drivers
    • \termdd.sys,"
    • LastScan = 0x4B74187A
    • Infected = 0x00000007
    • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
    • Use FormSuggest = "Yes"
    • HKEY_CURRENT_USER\Software\Microsoft\Multimedia\Video For Windows\MCIAVI
    • DefaultOptions = 0x00000000
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
    • WarnOnZoneCrossing = 0x00000000
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
    • Paladin Antivirus = ""%ProgramFiles%\Paladin Antivirus\pav.exe" -noscan"

Registry values midified

  • HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
    • Cookies =
    • Cache =
    • History =

Download

 

 

Articles connexes
Derniers articles
.
Information | Contact

© All Rights Reserved. net-studio.org 2009