WARNING!! PAV.EXE Personal Antivirus

Orbital Shark

New member
Guru
Gold Member
VIP
Local time
10:36 PM
Messages
6,298
Location
Milton Keynes, United Kingdom
   Note
I've not seen this for some time but it seems to be doing the rounds again so I thought i'd give everyone a heads up.


personalantivirus_img1.png

Personal Antivirus, or PersonalAntivirus, is a rogue anti-spyware program to come out from the company called Innovagest 2000.

Personal Antivirus is installed by a trojan called Zlob, which attempts to trick you into buying the alleged rogue anti-spyware program. Once you're infected with Zlob, a fake security message similar to a Windows notification pops up saying your PC is infected with malware. This Personal Antivirus message is used to lure you into purchasing, downloading and installing their program to remove the imaginary spyware.

Personal Antivirus may also automatically launch at your computer's startup and scan your computer. Personal Antivirus may be difficult to remove manually, and will continue to try to recreate itself. Personal Antivirus is a clone of Internet Antivirus Pro and General Antivirus, which are other corrupt distributed programs. Personal Antivirus should not be trusted and is recommended to be removed.

I have come across 4 machines over the last week that have been infected by this rediculously annoying 'antivirus' software.

Step by step removal:
I have found that advanced removal is the best method for this app.

1, You will need to end the PAV.EXE process in taskmanager. Right-click the taskbar and click 'Task Manager' then the 'Processes' tab. Next, find and right-click the PAV.EXE entry and select 'End Process Tree'. This will kill the process.


2, Delete the following folders from your computer
  • c:\program files\PersonalAV
  • c:\program files\Common Files\Uninstall\PersonalAV
  • c:\windows\tasks\PersonalAV
3, Run 'regedit' from the start menu and do a search for 'PersonalAV' and delete every entry found.
   Tip
It's best to run a second full search once the first has finished


Once all trace of the app has been removed you should re-boot your machine and you will find that the annoying tray notification applet has gone & all processes for PAV.EXE have been eliminated.
 

My Computer My Computer

Computer Manufacturer/Model Number
Compaq Desktop
OS
Windows 7 Ultimate x64
CPU
AMD Sempron Dual Core
Memory
3GB
Graphics Card(s)
NVIDIA GeForce 6150SE nForce 430
Screen Resolution
1024x768
Hard Drives
150GB Sata
Thanks for the heads up Orbital. If it's making it's way around again, that means I have to warn all of my volunteers/customers...again. lol
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
SuperBeast
OS
Windows 10 Tech Preview 9926 x64
CPU
AMD FX-8350
Motherboard
Gigabyte GA-990FXA-UD3
Memory
16GB DDR3 1333
Graphics Card(s)
Asus R9 290 DirectCU II OC, Gigabyte Windforce R9 290 OC
Sound Card
Integrated w/ Creative A250 2.1 speakers
Monitor(s) Displays
Main: Asus VN289H 28" Secondary: Acer G246HL 24"
Screen Resolution
1920x1080
Hard Drives
128 GB SanDisk Ultra Plus (Windows drive)

240 GB Crucial M500 SSD (Games drive)

1 TB WDC WD10EACS 7200RPM HDD (Data drive)

2 TB Seagate Expansion Desktop external HDD (Backup drive)
PSU
900w Antec HCG-900
Case
Raidmax Agusta Full ATX
Cooling
Corsair H80
Keyboard
Cooler Master Devastator MB24
Mouse
Cooler Master Devastator MS2K 1000/1600/2000 DPI
Internet Speed
100Mbps cable
Antivirus
Avast!
Browser
Chrome
Good job orbital, made it easy to follow and I have seen that on a few of my friends PC's I'll pass this page along to them. :)
 

My Computer My Computer

Computer Manufacturer/Model Number
Custom | Whitebox
OS
Windows 7 Ultimate, OS X 10.7, Ubuntu 11.04
CPU
Intel E6750 @ 3.80GHz
Motherboard
Gigabyte GA-EP45-UD3L (Revision 1.1)
Memory
2x2GB & 2x1GB (6GB) OCZ Reaper 1066MHz @ 1080MHz
Graphics Card(s)
EVGA nVidia GTX 260 896mb (216 Core) FTW Edition
Sound Card
Realtek ALC888
Monitor(s) Displays
21" VIZIO TV
Screen Resolution
1680x1050 @ 60Hz
Hard Drives
Western Digital WD6401AALS - 640GB
Hitachi HDP725016GLA380 - 160GB
PSU
Corsair 750W
Case
NZXT Nemesis Elite
Cooling
Thermaltake SpinQ
Keyboard
Logitech Wireless S520
Mouse
Logitech Wireless S520 - Microsoft Wireless Arc Mouse
Internet Speed
Download: 20mbps, Upload: 3mbps
thanks sharky for the heads up.

not seen this one for a while...

*waits for phone to start ringing*
 

My Computer My Computer

Computer Manufacturer/Model Number
mickey megabyte 1234
OS
ultimate 64 sp1
CPU
i5 2500K [email protected]
Motherboard
MSI P67A-GD53
Memory
8 gigs GSkill Ripjaws 1600
Graphics Card(s)
amd hd6950
Sound Card
creative x-fi gamer
Monitor(s) Displays
samsung 24"
Screen Resolution
1920x1080
Hard Drives
ocz vertex 2e 60 gig, samsung f3 1tb, buffalo 2tb ext
PSU
antec 550
Case
antec three hundred
Cooling
i'm a cooling fan
Keyboard
saitek eclipse ii
Mouse
logitech g3
Internet Speed
about 4 Mbps
Other Info
i love win7

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Me
OS
Win 7 Ultimate x64
CPU
FX-8350 @ 4.6 GHz so far
Motherboard
Asus M5A97 EVO
Memory
ADATA XPG V1 Series Black 8GB DDR3 1600
Graphics Card(s)
Sapphire R9 270x Dual-X
Sound Card
Xonar DGX w/ Corsair Vengence 1300
Monitor(s) Displays
Acer S232HL Abid
Screen Resolution
1920x1080
Hard Drives
120 GB OCZ Vertex 3
500 GB Seagate 7200.12
PSU
Antec Earthwatts 650W Green
Case
Antec Three Hundred
Cooling
Cooler Master 212 EVO
Keyboard
Logitech G510
Mouse
Logitech G500s
Internet Speed
35000/3000

My Computer My Computer

Computer Manufacturer/Model Number
Compaq Desktop
OS
Windows 7 Ultimate x64
CPU
AMD Sempron Dual Core
Memory
3GB
Graphics Card(s)
NVIDIA GeForce 6150SE nForce 430
Screen Resolution
1024x768
Hard Drives
150GB Sata
One thing about ZLob and *fake* Anti-virus or Anti-spyware pop-ups... once you see the alerts, it's already installed on the computer.

Most of the latest ZLob infections include a Rootkit (**Backdoor TDSS and more ...
A remote administration utility which bypasses normal security mechanisms to secretly control a program, computer or network). :mad:

These are often hard to get rid of, you can clean up a Rootkit (kind of)... but I am one who prefers not to. It's better to wipe and do a clean install your Windows OS. You cannot be sure that your OS is totally stable again without doing this.

** Virus Description: Backdoor:W32/TDSS
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Good tip... thanx. :thumbsup:
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build
OS
Windows 7 x64 Professional
CPU
Intel Core i7-870 Lynnfield 2.93 GHz
Motherboard
Intel Whitesburg P55 LGA1156
Memory
Kingston Hyper X 1333MHz DDR3 4x4Gb
Graphics Card(s)
Nvidia GTS 250
Monitor(s) Displays
AOC Q3279VWF 31.5"
Screen Resolution
2560x1440
Hard Drives
Western Digital 1000GB Hard Drive (SATA 3.0Gb/s, 7200rpm, 32MB Cache)
Verbatim 500GB (External)
PSU
650W
Case
Coolermaster HAF 912
Cooling
Stock
Keyboard
Logitech
Mouse
Logitech
Antivirus
Avira
Browser
Firefox
Other Info
LG OptDrive 24x SATA DVDRW Lightscribe
Thanks OS. :D I'll keep this in mind.
 

My Computer My Computer

Computer Manufacturer/Model Number
HP Compaq Presario/SR5113WM
OS
Windows 7 Ultimate x64/ Windows Vista Ultimate x64
CPU
AMD Athlon 64 X2 3600+ 1.9Ghz
Motherboard
Asus M2N68-LA
Memory
PNY Optima Memory DDR2 2GB 2x1 kit
Graphics Card(s)
PNY Nvidia 8400 GS 256MB
Sound Card
On board RealTek
Monitor(s) Displays
Acer X163W LCD
Screen Resolution
1366x768
Hard Drives
Western Digital 160 GB SATA 3G (3.0Gb/sec)
7200 rpm
Western Digital 160 GB IDE
PSU
Dynex 400w
Case
Nothin Special
Cooling
Stock
Keyboard
Standard 102 key with volume and sleep buttons
Mouse
Wireless Logitech LX7
Internet Speed
Comcrap 10mb cable
Other Info
Insignia 2.1 speakers, wireless Xbox 360 controller w/plug n play charger, Belkin wireless G + mimo usb network adapter.
Back
Top