Internet Explorer blocked :-( please help!

qwertyasdfg

VIP Member
VIP Member
Joined
Jul 23, 2005
Messages
1,039
Reaction score
55
Location
Labyrinth
Hello All,

I am having an issue with one of my family members work PC's, I think somehow they have managed to install a rogue anti-virus programme called personal antivirus.

This programme started spitting out annoying pop-ups from the task bar advising that there were various trojans and virus's on his computer and to press a button to either block them or another to ignore them, if one was to press either, an anti virus programme would start running and identifying various issues and then asks for one to purchase a license to fix the issue's, blatant scam I know!

I reckon I have managed to remove this programme by running various spyware apps but an issue still remains with internet explorer. If I launch IE, the first page i navigate to will display an error message just underneath the address bar advising somin along the lines of "malicious advertising code is in use on the site, click here to get personal antivirus to fix blah blah" once the page i am trying to navigate to is loaded, it remains for around a minute and then is re-directed to another page advising that the page is blocked and gives two tabs to either "continue unprotected" or "get security software".

Pressing any of the above mentioned tabs does nothing, I know its not the Mcafee Site advisor as that spits out a different page and advises you even before you get to the page you wanna view. This computer is installed with the latest LEGIT Mcafee antivirus suite, so I was quite surprised that it did not pick it up and remove the threat.

Any advise on how I could get rid of this virus/programme and make the IE function correctly again without having to wipe the whole computer would be great, byt the way Firefox works fine!

Thanks in advance for your time and help.


Warning! Visiting this site may harm your computer!
This web site probably contains malicious software program, which can cause damage to your computer or perform actions without your permission. Your computer may be infected after visiting such web site.

We recommend you to install (or activate) antivirus security software.

I do realize that visiting this site can cause harm to my computer.
 
Remove Personal Antivirus/PAV.exe (Removal Info) For XP/Vista try this place m8 all the info
googled it for you

another way
How to remove Personal Antivirus and affiliated threats manually:
Manual removal of Personal Antivirus is a feasible objective if you have sufficient expertise in dealing with program files, processes, .dll files and registry entries.

The files to be deleted are listed below:

* %Documents and Settings%\All Users\Desktop\Personal Antivirus.lnk
* %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus
* %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus\Personal Antivirus Home Page.lnk
* %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus\Personal Antivirus.lnk
* %Documents and Settings%\All Users\Start Menu\Programs\Personal Antivirus\Purchase License.lnk
* %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Personal Antivirus.lnk
* %UserProfile%\Application Data\Personal Antivirus
* %UserProfile%\Application Data\Personal Antivirus\settings.ini
* %UserProfile%\Application Data\Personal Antivirus\uill.ini
* %UserProfile%\Application Data\Personal Antivirus\unins000.exe
* %UserProfile%\Application Data\Personal Antivirus\Uninstall Personal Antivirus.lnk
* %UserProfile%\Application Data\Personal Antivirus\db
* %UserProfile%\Application Data\Personal Antivirus\db\config.cfg
* %UserProfile%\Application Data\Personal Antivirus\db\Timeout.inf
* %UserProfile%\Application Data\Personal Antivirus\db\Urls.inf
* %UserProfile%\Local Settings\Application Data\Microsoft\Windows\log.txt
* %UserProfile%\Local Settings\Application Data\Microsoft\Windows\pguard.ini
* %UserProfile%\Local Settings\Application Data\Microsoft\Windows\services.exe
* %Program Files%\Personal Antivirus
* %Program Files%\Personal Antivirus\activate.ico
* %Program Files%\Personal Antivirus\Explorer.ico
* %Program Files%\Personal Antivirus\PerAvir.exe
* %Program Files%\Personal Antivirus\unins000.dat
* %Program Files%\Personal Antivirus\uninstall.ico
* %Program Files%\Personal Antivirus\working.log
* %Program Files%\Personal Antivirus\db
* %Program Files%\Personal Antivirus\db\DBInfo.ver
* %Program Files%\Personal Antivirus\db\ia080614.db
* %Program Files%\Personal Antivirus\db\ia080618x.db
* %Program Files%\Personal Antivirus\Languages
* %Program Files%\Personal Antivirus\Languages\IAEs.lng
* %Program Files%\Personal Antivirus\Languages\IAFr.lng
* %Program Files%\Personal Antivirus\Languages\IAGer.lng
* %Program Files%\Personal Antivirus\Languages\IAIt.lng
* %WINDOWS%\system32\log.txt
* %UserProfile%\Application Data\Microsoft\Windows\winlogon.exe
* %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iGSh.png
* %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iMSh.png
* %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iPSh.png
* %UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iv.exe
* %UserProfile%\Local Settings\Application Data\Microsoft\Windows\log.txt
* %UserProfile%\Local Settings\Application Data\Microsoft\Windows\pguard.ini
* %UserProfile%\Local Settings\Application Data\Microsoft\Windows\services.exe

The registry entries that need to be removed are as follows:

* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Personal Antivirus_is1
* HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ITGRDENGINE
* HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ITGrdEngine
* HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer “PrS”
* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Personal Antivirus”

Please, be aware that manual removal of Personal Antivirus is a cumbersome process and does not always ensure complete deletion of the malware, due to the fact that some files might be hidden or may get reanimated automatically afterwards. Moreover, manual interference of this kind may cause damage to the system. That’s why we strongly recommend automatic removal of Personal Antivirus, which will save your time and enable avoiding any system malfunctions and guarantee the needed result.
 
As always boot into safe mode to remove malware etc.

Remove Personal Antivirus/PAV.exe (Removal Info) For XP/Vista try this place m8 all the info
googled it for you

another way
How to remove Personal Antivirus and affiliated threats manually:
Manual removal of Personal Antivirus is a feasible objective if you have sufficient expertise in dealing with program files, processes, .dll files and registry entries...

If none of that works give malware bytes ago.

For what it's worth I recommend dumping McAfee and get a well reviewed AV software like AVG-Free, Comodo, Nod32 or Kaspersky.
 
Last edited:
I came across this little nasty fixing a pc 2wks ago and tbh as little-pob said
malwarebytes seen it off ok ..
To also highlight what pob said make sure you do it in safe mode.
 
when i got infected googled it and got a removal tut that basicly just said use malware bytes with a guide on how to run a scan! - so I did and no probs so far (about 2 weeks ago)
 
Back
Top