|
Free malware removal tool to remove Paladin Antivirus
|
|
Écrit par Administrator |
Samedi, 27 Février 2010 14:46
|
|
There are no translations available. Paladin Antivirus is a rogue Antispyware, a scareware, it's a malware that pretends to be an Antivirus. It is a wolf in sheep's clothing. It conducts a fake scan of your system; you are warned by a fake alarm that there are more malwares on your system. It’s true indeed, there is really a malware in your system but I think the only malware on your system is Paladin Antivirus. It invites you to purchase a license to remove malwares, do not, it's a scam, you need a license for a malware? This so-called Antivirus tries to scam you. Uninstall Paladin Antivirus immediately from your system using this free removal tool for Paladin Antivirus.

To remove Paladin Antivirus (Uninstall Paladin Antivirus)
- Download this free removal tool for Paladin Antivirus
- Extract it
- Launch
- Click on the delete button
Paladin Antivirus will be removed from your system in 10s. Restart your computer when it’s finished.

Processes :
Files :
- %AppData%\Microsoft\Internet Explorer\Quick Launch\Paladin Antivirus.lnk
- %Desktop%\Paladin Antivirus Support.lnk
- %Desktop%\Paladin Antivirus.lnk
- %StartMenu%\Programs\Paladin Antivirus
- %StartMenu%\Programs\Paladin Antivirus\Paladin Antivirus Support.lnk
- %StartMenu%\Programs\Paladin Antivirus\Paladin Antivirus.lnk
- %StartMenu%\Programs\Paladin Antivirus\Uninstall Paladin Antivirus.lnk
- %System%\wbem\Performance\WmiApRpl_new.ini
- %ProgramFiles%\Paladin Antivirus
- %ProgramFiles%\Paladin Antivirus\help.ico
- %ProgramFiles%\Paladin Antivirus\pav.db
- %ProgramFiles%\Paladin Antivirus\pav.exe
- %ProgramFiles%\Paladin Antivirus\pavext.dll
- %ProgramFiles%\Paladin Antivirus\phook.dll
- %ProgramFiles%\Paladin Antivirus\uninstall.exe
- %Temp%\4otjesjty.mof
- %Temp%\pav.dat
- %Temp%\pavr.dat
Registry
Registry keys created
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Paladin Antivirus
- HKEY_LOCAL_MACHINE\SOFTWARE\Paladin Antivirus
- HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings
- HKEY_LOCAL_MACHINE\SOFTWARE\Paladin Antivirus
- HKEY_CURRENT_USER\Software\Microsoft\Multimedia\Video For Windows
- HKEY_CURRENT_USER\Software\Microsoft\Multimedia\Video For Windows\MCIAVI
Registry values created
- HKEY_LOCAL_MACHINE\SOFTWARE\Paladin Antivirus
- Settings_0 = 0x00000001
- SecStatus_3 = 0x00000001
- SecStatus_4 = 0x00000001
- SecStatus_5 = 0x00000001
- FD = 0x00000000
- GUID = "691210486911968069118321"
- Data = ":1920:2040:2160:2280:2400:2520:2640:2880:3000:3120:"
- swver = "3.0"
- dbver = "1.1"
- dbsigns = "62577"
- dbverf = "1.1"
- dbsignsf = "62577"
- InfectedFiles = "%System%\slbcsp.dll,%System%\themeui.dll,%System%\w32time.dll,%System%
- \WPWIZDLL.DLL,%System%\Wbem\subscrpt.mof,%System%\Drivers\cinemst2.sys,%System%\Drivers
- \termdd.sys,"
- LastScan = 0x4B74187A
- Infected = 0x00000007
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
- Use FormSuggest = "Yes"
- HKEY_CURRENT_USER\Software\Microsoft\Multimedia\Video For Windows\MCIAVI
- DefaultOptions = 0x00000000
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
- WarnOnZoneCrossing = 0x00000000
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
- Paladin Antivirus = ""%ProgramFiles%\Paladin Antivirus\pav.exe" -noscan"
Registry values midified
- HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
- Cookies =
- Cache =
- History =

|