Saturday, March 27, 2010

XP Defender to capture the Bare Essentials for System Functioning

XP Defender (XPDefender) might deprive computer system infected with its trialware of the bare essentials to run so that it cannot operate properly or its functioning is the altering of freezes and sudden reboots. Naturally you computer system gets not into such a state at once as you are provided with option to buy XP Defender while its chromes and alerts are being shown assuring you that your system is badly affected with viruses. If you buy XP Defender, that does not improve it a bit and its annoying ads will grow even nastier. You need to remove XP Defender as a No. 1 virus, as well as to get rid of XP Defender allies known to facilitate its activities and to make users download and install the scamware and even to inject the rogue against their will.
Click here to start free system scan and to execute safe and quick XP Defender removal.

XP Defender screenshot:

XP Defender removal tool:

XP Defender manual removal guide:
Delete XP Defender files:
ave.exe

Delete XP Defender registry entries:
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command “(Default)” = “av.exe” /START “%1? %*
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command “(Default)” = “av.exe” /START “%1? %*
HKEY_CLASSES_ROOT\.exe\shell\open\command “(Default)” = “av.exe” /START “%1? %*
HKEY_CLASSES_ROOT\secfile\shell\open\command “(Default)” = “av.exe” /START “%1? %*
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = “av.exe” /START “firefox.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command “(Default)” = “av.exe” /START “firefox.exe” -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command “(Default)” = “av.exe” /START “iexplore.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “AntiVirusOverride” = “1?
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “FirewallOverride” = “1?

No comments: