Wednesday, November 7, 2012

Remove XP Antivirus Pro 2013 – hijacker and full-featured counterfeit extermination powered by free scanner

XP Antivirus Pro 2013 is selected by visitors of websites that fake online scan. The faking is a mere animation that hackers want us to treat as a reflection of a visiting computer inspection for viruses. Once you have been redirected to one of such sites you may have already got your PC infected with browser redirect, especially if you are experiencing recurrent openings of the fake scanner. Consequentially, there is a kind of preliminary, in advance removal of XP Antivirus Pro 2013: extermination of the hijacker. On the other hand, many get their PCs infected without ever visiting websites adverting the deceptive tool, for there are plenty of other approaches to introducing the counterfeit, including that based on trojan droppers, spam. Once the rogue has been installed, it changes host system settings so as to be able to show its silly popups in response to user’s attempts of launching executables. Worst of it is that programs one is trying to start may fail to launch their processes being affected by the malware. Therefore, instead of opening, e.g. MS Word, you may get a balloon alert on tracking software found and a user’s interface of the misleading antivirus. To get rid of XP Antivirus Pro 2013, true viruses, as well as get your PC protected by true antivirus on free scan terms, click here


XP Antivirus Pro 2013 may display following alerts:
    XP Antivirus Pro 2013 Firewall Alert
    XP Antivirus Pro 2013 has blocked a program from accessing the internet
    Internet Explorer is infected with Trojan-BNK.Win32.Keylogger.gen
    Private data can be stolen by third parties, including credit card details and passwords.

    Severe system damage!
    Spyware and viruses detected in the background. Sensitive system components under attack! Data loss, identity theft and system corruption are possible. Act now, click here for a free security scan.

    Virus intrusion!
    Your computer security is at risk. Spyware, worms and Trojans were detected in the background. Prevent data corruption and credit card information theft. Safeguard your system and perform a free security scan now.

    System danger!
    Your system security is in danger. Privacy threats detected. Spyware, keyloggers or Trojans may be working in the background right now. Perform an in-depth scan and removal now, click here.
XP Antivirus Pro 2013 activation key \ unlock code (will disable fake alerts):

0W000-000B0-00T00-E0020
XP Antivirus Pro 2013 remover:

Manual removal directions:

Delete infected files:
%CommonAppData%\
%LocalAppData%\
%LocalAppData%\.exe
%Temp%\
%UserProfile%\Templates\ 

Delete infected registry entries:
HKEY_CURRENT_USER\Software\Classes\.exe "(Default)" = ''
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1" %*
HKEY_CLASSES_ROOT\
HKEY_CURRENT_USER\Software\Classes\ "(Default)" = 'Application'
HKEY_CURRENT_USER\Software\Classes\\DefaultIcon "(Default)" = '%1'
HKEY_CURRENT_USER\Software\Classes\\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1" %*
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1" %*
HKEY_CLASSES_ROOT\ah\shell\open\command "(Default)" = "%LocalAppData%\.exe" -a "%1" %*
HKEY_CLASSES_ROOT\ah\shell\open\command "IsolatedCommand"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = ""%LocalAppData%\.exe -a "C:\Program Files\Mozilla Firefox\firefox.exe""
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = ""%LocalAppData%\.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = ""%LocalAppData%\.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"" 

No comments: