Saturday, April 30, 2011

XP Anti-Spyware 2011 Removal for PC Independence

Hackers issue viruses. Many IT experts dedicate themselves to preventing   virus mass-spreading. However, the current solution is a PC specific protection, because the web provides great liberties for swindlers to block viruses before approaching computer systems. PC specific protection means a security solution (antiviris) is to be installed on a PC or else the PC is vulnerable to viruses.
Some of the swindlers have invented other viruses in that connection. XP Anti-Spyware 2011 is one of such recent viruses, which pretend to replace a protection for computer system. However, it should not be confused with a mere fake antivirus.
A fake antivirus is only aimed on faking security solution to be rewarded as though it is providing security services. In case of the rogue in question, the scam goes beyond as the counterfeiting has become a secondary purpose of the adverting infection introduction. The aim is to keep genuine security tools off a compromised machine and thus to turn such machine into a bot governed by remote hackers.
Get rid of XP Anti-Spyware 2011 to prevent your PC from becoming a slave to hackers. XP Anti-Spyware 2011 removal tool and free scanner is ready for download here. The link is ban-protected. If any difficulties occur in the course if using the link, please restart your PC is Safe Mode with Networking (tip for Windows XP users) and try again.

XP Anti-Spyware 2011 screenshot:


XP Anti-Spyware 2011 remover download:


XP Anti-Spyware 2011 manual removal instructions:
Delete infected files:
%UserProfile%\AppData\Local\pw.exe
%UserProfile%\AppData\Local\MSASCui.exe
%UserProfile%\Local Settings\Application Data\pw.exe
%UserProfile%\Local Settings\Application Data\MSASCui.exe
Delete infected registry entries:
HKEY_CURRENT_USER\Software\Classes\pezfile
HKEY_CLASSES_ROOT\pezfile
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "%1" %*
HKEY_CURRENT_USER\Software\Classes\pezfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "%1" %*
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "%1" %*
HKEY_CLASSES_ROOT\pezfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "%1" %*
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "C:\Program Files\Internet Explorer\iexplore.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = "1"

1 comment:

Anonymous said...

to remove mannualy it is not allowing to get into registry edit