Home > Threats > Personal Antivirus

What is Personal Antivirus

Posted on 15 September 2009 under Rogue Programs

1. What is Personal Antivirus?

It's unreliable and insecure computer application, pretending to be antivirus tool, but in fact it is known as a rogue program.

Right after Personal Antivirus has been transferred to computer, it will begin system scan process and generate report after the scan has been completed, making user an impression of an ordinary antivirus program. But going further into the matter, transparent lie is noticed. In scan results, legitimate Windows files such as explorer.exe, regedit.exe, notepad.exe are defined as Password Stealers, HijackThis setup file HJTInstall.exe is defined as a Trojan. These are only a few examples of entire fake report.

Personal Antivirus will act as a scareware. It will pop messages "Worm Found", "Trojan Found", Windows Meta File vulnerability", "Security Violation Error", suggesting user to ignore or block assumed threats by purchasing licensed program version.

Personal Antivirus will start every time Windows are booted. An icon in a shape of a shield is visible in the taskbar area. Add/Remove Programs will not display Personal Antivirus, but an entry in Start menu is created. Trying to uninstall the program through Start menu by choosing Uninstall will not work.

2. Personal Antivirus screen shot:

Personal Antivirus

3. How to remove Personal Antivirus:

  1. Internet connection might be disabled or Internet browser might be blocked by Personal Antivirus, so it won't be possible to download any files to infected computer. In this case please download all files required for Personal Antivirus removal to another computer and then transfer them on the infected one using CD/DVD or USB flash drive.
  2. To remove Personal Antivirus download Spyware Doctor and install the program (for the installation guide click here). Before installation, make sure all other programs and windows are closed.
  3. After the installation, computer scan should be started automatically. If so, please move to the next step. If not, click "Status" on the left side menu and press "Scan Now" button to run computer scanner as shown in the picture below:

  4. After the scan has been completed and scan results have been generated, press "Fix Checked" button to remove Personal Antivirus.

  5. Restart the computer to complete Personal Antivirus removal procedure.

4. Personal Antivirus files:

C:\Program Files\PersonalAV\PersonalAV.exe

5. Hijackthis entries:

O4 - HKLM\..\Run: [PersonalAV] C:\Program Files\PersonalAV\PersonalAV.exe