Tuesday, October 2, 2012

XP Defender 2013 virus.

XP Defender 2013 program. The whole truth

XP Defender 2013 is a new computer virus that bombards the Internet users. This virus claims to be a real antivirus. The reason of such behaviour is that it wants to steal your money bewildering you. When XP Defender 2013 gets inside the system it automatically scans it and provides you with the results of this scanning. And then it suggests you to purchase is commercial version to proceed with the removal of all allegedly detected bugs. But there is no commercial version of this program at all.

Be very careful with XP Defender 2013 virus. If you do the purchase you will get nothing but lost time and money. And the virus will completely achieve its goal. Remember! The only threat inside your system is XP Defender 2013 virus, all others allegedly detected by XP Defender 2013 are invented to scary you. It goes without saying that this program is not capable for anything good and is worth to be deleted without lingering.

XP Defender 2013 virus cleanup procedure:

  • Run GridinSoft Trojan Killer: Click Win+R and type the direct link for the program’s downloading. http://trojan-killer.net/download.php
  • If your PC is totally blocked and any attemps to launch the computer in such manner are in vain, use this method: take your USB flash drive / Memory Stick and download GridinSoft Trojan Killer installation file from this site http://trojan-killer.net/download.php and save it to your USB flash drive / Memory Stick. Get back to your infected PC and insert the USB Drive / Memory Stick into the respective USB slot.
  • Install GridinSoft Trojan Killer. Right click – Run as. Uncheck the checkbox as displayed below.
  • Note!

    Don’t uncheck the Start Trojan Killer checkbox at the end of installation! checkbox

Manual removal guide of XP Defender 2013 virus:

Delete XP Defender 2013 files:

  • %LocalAppData%\[rnd_2]
  • %Temp%\[rnd_2]
  • %UserProfile%\Templates\[rnd_2]
  • %CommonApplData%\[rnd_2]

Delete XP Defender 2013 registry entries:

  • HKEY_CURRENT_USER\Software\Classes\.exe
  • HKEY_CURRENT_USER\Software\Classes\.exe\ [rnd_0]
  • HKEY_CURRENT_USER\Software\Classes\.exe\Content Type application/x-msdownload
  • HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon
  • HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon\ %1
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\open
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command\ “[rnd_1].exe” -a “%1″ %*
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command\IsolatedCommand “%1″ %*
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command\ “%1″ %*
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command\IsolatedCommand “%1″ %*
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]\ Application
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]\Content Type application/x-msdownload
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]\DefaultIcon
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]\DefaultIcon\ %1
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell\open
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell\open\command
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell\open\command\ “[rnd_1].exe” -a “%1″ %*
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell\open\command\IsolatedCommand “%1″ %*
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell\runas
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell\runas\command
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell\runas\command\ “%1″ %*
  • HKEY_CURRENT_USER\Software\Classes\[rnd_0]\shell\runas\command\IsolatedCommand “%1″ %*

The source of the information http://www.deletemalware.net/xp-defender-2013-scam-delete-it/

No comments:

Post a Comment