<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Emsisoft New Malware Blog &#187; Removal Help</title>
	<atom:link href="http://www.anti-malware-blog.com/category/removal-help/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.anti-malware-blog.com</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Wed, 25 Jan 2012 06:47:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Antivirus Smart Protection Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 25 Jan 2012 06:47:18 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Antivirus Smart Protection]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2807</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Antivirus Smart Protection. Emsisoft Anti-Malware detects this malware as Rogue.Win32.AntivirusSmartProtection. Antivirus Smart Protection is a rogue scanner application, another variant of Malware Protection Center and Internet Security Guard. A rogue application tries to trick you by displaying false positive or misleading scan results [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Antivirus Smart Protection</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.AntivirusSmartProtection" href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirusSmartProtection" target="_blank"><strong>Rogue.Win32.AntivirusSmartProtection</strong></a><strong>.</strong></p>
<p><strong>Antivirus Smart Protection </strong><strong></strong>is a rogue scanner application, another variant of <a title="Malware Protection Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.MalwareProtectionCenter"><strong>Malware Protection Center</strong></a> and <a title="Rogue.Win32.InternetSecurityGuard" href="http://www.emsisoft.com/en/malware/?Adware.Win32.InternetSecurityGuard" target="_blank"><strong>Internet Security Guard</strong></a>. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\5c678c\</li>
<li>%AllUsersProfile%\Application Data\5c678c\sqlite3.dll</li>
<li>%AllUsersProfile%\Application Data\5c678c\ASPSys\</li>
<li>%AllUsersProfile%\Application Data\5c678c\BackUp\</li>
<li>%AllUsersProfile%\Application Data\5c678c\Quarantine Items\</li>
<li>%AllUsersProfile%\Application Data\5c678c\582.mof</li>
<li>%AllUsersProfile%\Application Data\5c678c\AS9c5_8046.exe</li>
<li>%AllUsersProfile%\Application Data\5c678c\ASP.ico</li>
<li>%AllUsersProfile%\Application Data\5c678c\mozcrt19.dll</li>
<li>%AllUsersProfile%\Application Data\ASLNP\</li>
<li>%AllUsersProfile%\Application Data\ASLNP\ASUUDJRRJXP.cfg</li>
<li>%AppData%\Antivirus Smart Protection\</li>
<li>%AppData%\Antivirus Smart Protection\cookies.sqlite</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\Antivirus Smart Protection.lnk</li>
<li>%UserProfile%\Desktop\Antivirus Smart Protection.lnk</li>
<li>%Temp%\scandsk211d_8046.exe</li>
<li>%UserProfile%\Start Menu\Antivirus Smart Protection.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Antivirus Smart Protection.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\Classes\AS9c5_8046.DocHostUIHandler<br />
Default = Implements DocHostUIHandler<br />
Clsid  = {3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\Classes\clsid\{3F2BBC05-40DF-11D2-9455-00104BC936FF}<br />
Default = Implements DocHostUIHandler<br />
LocalServer32  = %AllUsersProfile%\Application Data\5c678c\AS9c5_8046.exe<br />
ProgID  = AS9c5_8046.DocHostUIHandler</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cl.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frmwrk32.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\homeav2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init32.exe \<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MalwareRemoval.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ozn695m5.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsAuxs.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsGui.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsSvc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsTray.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PC_Antispyware2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfndr.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PerAvir.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protector.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qh.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quick Heal.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\QuickHealCleaner.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Save.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveArmor.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveDefense.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveKeep.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secure Veteran.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\secureveteran.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Security Center.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SecurityFighter.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\securitysoldier.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smart.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartprotector.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smrtdefp.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftSafeness.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spywarexpguard.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrustWarrior.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\W3asbas.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windll32.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows Police Pro.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpdeluxe.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~1.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~2.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\3</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\<br />
ltTST = 7F3E0000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures = no<br />
RunInvalidSignatures = 01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\<br />
Home Security Solutions = “%AllUsersProfile%\Application Data\5c678c\AS9c5_8046.exe” /s /d</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\RunOnce\<br />
HSS = “%Temp%\scandsk211d_8046.exe” /cs:1</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Antivirus-Smart-Protection-1.png"><img class="alignnone size-medium wp-image-2808" title="Antivirus Smart Protection" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Antivirus-Smart-Protection-1-400x291.png" alt="Antivirus Smart Protection" width="400" height="291" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Antivirus-Smart-Protection-2.png"><img class="alignnone size-medium wp-image-2809" title="Antivirus Smart Protection" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Antivirus-Smart-Protection-2-400x292.png" alt="Antivirus Smart Protection" width="400" height="292" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Antivirus-Smart-Protection-3.png"><img class="alignnone size-medium wp-image-2810" title="Antivirus Smart Protection" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Antivirus-Smart-Protection-3-400x197.png" alt="Antivirus Smart Protection" width="400" height="197" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Antivirus-Smart-Protection-4.png"><img class="alignnone size-medium wp-image-2811" title="Antivirus Smart Protection" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Antivirus-Smart-Protection-4-400x303.png" alt="Antivirus Smart Protection" width="400" height="303" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Antivirus-Smart-Protection-5.png"><img class="alignnone size-medium wp-image-2812" title="Antivirus Smart Protection" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Antivirus-Smart-Protection-5-400x274.png" alt="Antivirus Smart Protection" width="400" height="274" /></a></p>
<p>To register and uninstall this rogue application, you can try one of the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>K7LY-R5GU-SI9D-EVFB</strong><strong></strong><strong>
U2FD-S2LA-H4KA-UEPB</strong></span></pre>
<p><strong>How to remove the infection of Antivirus Smart Protection </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirusSmartProtection" target="_blank">Rogue.Win32.AntivirusSmartProtection</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/12/26/home-security-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Home Security Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/03/22/cleanup-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">CleanUP Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/08/guard-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Guard Pro Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware Protection Center Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 14:27:18 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Protection Center]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2800</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Malware Protection Center. Emsisoft Anti-Malware detects this malware as Rogue.Win32.MalwareProtectionCenter. Malware Protection Center is a rogue scanner application, another variant of Internet Security Guard. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Malware Protection Center</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.MalwareProtectionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.MalwareProtectionCenter" target="_blank"><strong>Rogue.Win32.MalwareProtectionCenter</strong></a><strong>.</strong></p>
<p><strong>Malware Protection Center </strong><strong></strong>is a rogue scanner application, another variant of <a title="Rogue.Win32.InternetSecurityGuard" href="http://www.emsisoft.com/en/malware/?Adware.Win32.InternetSecurityGuard" target="_blank"><strong>Internet Security Guard</strong></a>. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\5c678c\</li>
<li>%AllUsersProfile%\Application Data\5c678c\sqlite3.dll</li>
<li>%AllUsersProfile%\Application Data\5c678c\BackUp\</li>
<li>%AllUsersProfile%\Application Data\5c678c\MPCSys\</li>
<li>%AllUsersProfile%\Application Data\5c678c\Quarantine Items\</li>
<li>%AllUsersProfile%\Application Data\5c678c\73.mof</li>
<li>%AllUsersProfile%\Application Data\5c678c\mozcrt19.dll</li>
<li>%AllUsersProfile%\Application Data\5c678c\MP5c6_8040.exe</li>
<li>%AllUsersProfile%\Application Data\5c678c\MPC.ico</li>
<li>%AllUsersProfile%\Application Data\MPJCENSJC\</li>
<li>%AllUsersProfile%\Application Data\MPJCENSJC\MPSJQIC.cfg</li>
<li>%AppData%\Malware Protection Center\</li>
<li>%AppData%\Malware Protection Center\cookies.sqlite</li>
<li>%AppData%\Malware Protection Center\Instructions.ini</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\Malware Protection Center.lnk</li>
<li>%UserProfile%\Desktop\Malware Protection Center.lnk</li>
<li>%UserProfile%\Start Menu\Malware Protection Center.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Malware Protection Center.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\Classes\clsid\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\<br />
Default = Implements DocHostUIHandler<br />
LocalServer32  = %AllUsersProfile%\Application Data\5c678c\MP5c6_8040.exe<br />
ProgID  = MP5c6_8040.DocHostUIHandler</li>
<li>HKEY_LOCAL_MACHINE\Software\Classes\MP5c6_8040.DocHostUIHandler\<br />
Default  = Implements DocHostUIHandler<br />
Clsid  = {3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cl.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frmwrk32.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\homeav2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init32.exe \<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MalwareRemoval.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ozn695m5.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsAuxs.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsGui.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsSvc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsTray.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PC_Antispyware2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfndr.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PerAvir.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protector.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qh.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quick Heal.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\QuickHealCleaner.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Save.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveArmor.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveDefense.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveKeep.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secure Veteran.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\secureveteran.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Security Center.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SecurityFighter.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\securitysoldier.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smart.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartprotector.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smrtdefp.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftSafeness.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spywarexpguard.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrustWarrior.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\W3asbas.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windll32.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows Police Pro.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpdeluxe.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~1.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~2.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\3</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\<br />
ltTST = 7F3E0000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures = no<br />
RunInvalidSignatures = 01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\<br />
Malware Protection Center = “%AllUsersProfile%\Application Data\5c678c\MP5c6_8040.exe” /s /d</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\RunOnce\<br />
MPC = “%Temp%\setup.exe” /cs:1</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/MalwareProtectionCenter-1.png"><img class="alignnone size-medium wp-image-2801" title="Malware Protection Center (Rogue.Win32.MalwareProtectionCenter)" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/MalwareProtectionCenter-1-400x291.png" alt="Malware Protection Center (Rogue.Win32.MalwareProtectionCenter)" width="400" height="291" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/MalwareProtectionCenter-2.png"><img class="alignnone size-medium wp-image-2802" title="Malware Protection Center (Rogue.Win32.MalwareProtectionCenter)" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/MalwareProtectionCenter-2-400x291.png" alt="Malware Protection Center (Rogue.Win32.MalwareProtectionCenter)" width="400" height="291" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/MalwareProtectionCenter-3.png"><img class="alignnone size-medium wp-image-2803" title="Malware Protection Center (Rogue.Win32.MalwareProtectionCenter)" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/MalwareProtectionCenter-3-400x197.png" alt="Malware Protection Center (Rogue.Win32.MalwareProtectionCenter)" width="400" height="197" /></a></p>
<p>To register and uninstall this rogue application, you can try one of the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>K7LY-R5GU-SI9D-EVFB</strong> <strong>
K7LY-H4KA-SI9D-U2FD</strong> <strong>
U2FD-S2LA-H4KA-UEPB</strong></span></pre>
<p><strong>How to remove the infection of Malware Protection Center </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MalwareProtectionCenter" target="_blank">Rogue.Win32.MalwareProtectionCenter</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Smart Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/12/26/home-security-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Home Security Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/08/guard-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Guard Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/03/22/cleanup-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">CleanUP Antivirus Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Smart Protection 2012 Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/01/23/smart-protection-2012-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/01/23/smart-protection-2012-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 23 Jan 2012 13:52:18 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Smart Protection 2012]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2796</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Smart Protection 2012. Emsisoft Anti-Malware detects this malware as Rogue.Win32.SmartProtection2012. Smart Protection 2012 is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Smart Protection 2012</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.SmartProtection2012" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartProtection2012" target="_blank"><strong>Rogue.Win32.SmartProtection2012</strong></a><strong>.</strong></p>
<p><strong>Smart Protection 2012 </strong><strong></strong>is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\</li>
<li>%AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\B7E85B320179A6C600266C1CD151FC4E</li>
<li>%AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\B7E85B320179A6C600266C1CD151FC4E.exe</li>
<li>%UserProfile%\Desktop\Smart Protection 2012.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Smart Protection 2012\</li>
<li>%UserProfile%\Start Menu\Programs\Smart Protection 2012\Smart Protection 2012.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\RunOnce\<br />
B7E85B320179A6C600266C1CD151FC4E = %AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\B7E85B320179A6C600266C1CD151FC4E.exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Uninstall\Smart Protection 2012\<br />
DisplayName = Smart Protection 2012<br />
ShortcutPath = &#8220;%AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\B7E85B320179A6C600266C1CD151FC4E.exe&#8221; Uninstall<br />
UninstallString = &#8220;%AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\B7E85B320179A6C600266C1CD151FC4E.exe&#8221; Uninstall<br />
DisplayIcon = %AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\B7E85B320179A6C600266C1CD151FC4E.exe,0</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/SmartProtection2012.png"><img class="alignnone size-medium wp-image-2797" title="Smart Protection 2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/SmartProtection2012-400x298.png" alt="Smart Protection 2012" width="400" height="298" /></a></p>
<p>To register this rogue application, you can use any email and try the following serial number:</p>
<pre><strong></strong><span style="color: #ff0000;"><strong>AA39754E-715219CE</strong></span></pre>
<p><strong>How to remove the infection of Smart Protection 2012 </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartProtection2012" target="_blank">Rogue.Win32.SmartProtection2012</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/23/internet-security-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Smart Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/03/security-sphere-2012-removal-instructions/" rel="bookmark" class="crp_title">Security Sphere 2012 Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Security 2012 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/25/cloud-av-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Cloud AV 2012 Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/01/23/smart-protection-2012-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Internet Security 2012 Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/01/23/internet-security-2012-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/01/23/internet-security-2012-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 23 Jan 2012 12:56:37 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Internet Security 2012]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2790</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Internet Security 2012. Emsisoft Anti-Malware detects this malware as Rogue.Win32.InternetSecurity2012. Internet Security 2012 is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Internet Security 2012</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.InternetSecurity2012" href="http://www.emsisoft.com/en/malware/?Adware.Win32.InternetSecurity2012" target="_blank"><strong>Rogue.Win32.InternetSecurity2012</strong></a><strong>.</strong></p>
<p><strong>Internet Security 2012 </strong><strong></strong>is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\isecurity.exe</li>
<li>%AllUsersProfile%\Desktop\Internet Security 2012.lnk</li>
<li>%UserProfile%\Start Menu\Internet Security 2012.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run<br />
Internet Security 2012 = %AllUsersProfile%\Desktop\Internet Security 2012.lnk</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/InternetSecurity2012.png"><img class="alignnone size-medium wp-image-2791" title="Internet Security 2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/InternetSecurity2012-400x271.png" alt="Internet Security 2012" width="400" height="271" /></a></p>
<p>To register this rogue application, you can use any email and try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong></strong><strong>Y86REW-T75FD5-U9VBF4A</strong></span></pre>
<p><strong>How to remove the infection of Internet Security 2012 </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.InternetSecurity2012" target="_blank">Rogue.Win32.InternetSecurity2012</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/23/smart-protection-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Smart Protection 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/03/security-sphere-2012-removal-instructions/" rel="bookmark" class="crp_title">Security Sphere 2012 Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/06/security-guard-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Guard 2012 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Security 2012 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/19/xp-home-security-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">XP Home Security 2012 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/01/23/internet-security-2012-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Internet Security Guard Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 16 Jan 2012 13:19:44 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Internet Security Guard]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2779</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Internet Security Guard. Emsisoft Anti-Malware detects this malware as Rogue.Win32.InternetSecurityGuard. Internet Security Guard is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Internet Security Guard</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.InternetSecurityGuard" href="http://www.emsisoft.com/en/malware/?Adware.Win32.InternetSecurityGuard" target="_blank"><strong>Rogue.Win32.InternetSecurityGuard</strong></a><strong>.</strong></p>
<p><strong>Internet Security Guard </strong><strong></strong>is                            a                                          rogue                                    application. A rogue application tries to   trick  you     by     displaying false    positive or  misleading scan   results   report,     which  says   that your    computer has a    problem, or  infected  with     viruses or  trojan,   but    you will   not be able to   fix it before    you   purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\5c678c\</li>
<li>%AllUsersProfile%\Application Data\5c678c\Quarantine Items\</li>
<li>%AllUsersProfile%\Application Data\5c678c\BackUp\</li>
<li>%AllUsersProfile%\Application Data\5c678c\ISGSys\</li>
<li>%AllUsersProfile%\Application Data\5c678c\5285.mof</li>
<li>%AllUsersProfile%\Application Data\5c678c\IS5c6_8027.exe</li>
<li>%AllUsersProfile%\Application Data\5c678c\ISG.ico</li>
<li>%AllUsersProfile%\Application Data\5c678c\mozcrt19.dll</li>
<li>%AllUsersProfile%\Application Data\5c678c\sqlite3.dll</li>
<li>%AllUsersProfile%\Application Data\ISVLVYG\</li>
<li>%AllUsersProfile%\Application Data\ISVLVYG\ISVJG.cfg</li>
<li>%AppData%\Internet Security Guard\</li>
<li>%AppData%\Internet Security Guard\Instructions.ini</li>
<li>%AppData%\Internet Security Guard\cookies.sqlite</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\Internet Security Guard.lnk</li>
<li>%UserProfile%\Desktop\Internet Security Guard.lnk</li>
<li>%UserProfile%\Start Menu\Internet Security Guard.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Internet Security Guard.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\clsid\{3F2BBC05-40DF-11D2-9455-00104BC936FF}<br />
(Default)  = Implements DocHostUIHandler<br />
LocalServer32  = %AllUsersProfile%\Application Data\5c678c\IS5c6_8027.exe<br />
ProgID  = IS5c6_8027.DocHostUIHandler</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\IS5c6_8027.DocHostUIHandler<br />
(Default)  = Implements DocHostUIHandler<br />
Clsid  = {3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cl.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frmwrk32.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\homeav2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init32.exe \<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MalwareRemoval.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ozn695m5.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsAuxs.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsGui.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsSvc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsTray.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PC_Antispyware2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfndr.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PerAvir.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protector.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qh.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quick Heal.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\QuickHealCleaner.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Save.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveArmor.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveDefense.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveKeep.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secure Veteran.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\secureveteran.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Security Center.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SecurityFighter.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\securitysoldier.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smart.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartprotector.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smrtdefp.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftSafeness.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spywarexpguard.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrustWarrior.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\W3asbas.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windll32.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows Police Pro.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpdeluxe.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~1.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~2.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\3</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\<br />
ltTST = 7F3E0000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures = no<br />
RunInvalidSignatures = 01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\<br />
Home Security Solutions = “%AllUsersProfile%\Application Data\5c678c\IS5c6_8027.exe” /s /d</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\RunOnce\<br />
HSS = “%Temp%\%malwarefile%.exe” /cs:1</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.InternetSecurityGuard_1.png"><img class="alignnone size-medium wp-image-2780" title="Rogue.Win32.InternetSecurityGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.InternetSecurityGuard_1-400x292.png" alt="Rogue.Win32.InternetSecurityGuard" width="400" height="292" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.InternetSecurityGuard_2.png"><img class="alignnone size-medium wp-image-2781" title="Rogue.Win32.InternetSecurityGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.InternetSecurityGuard_2-400x292.png" alt="Rogue.Win32.InternetSecurityGuard" width="400" height="292" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.InternetSecurityGuard_3.png"><img class="alignnone size-medium wp-image-2782" title="Rogue.Win32.InternetSecurityGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.InternetSecurityGuard_3-400x225.png" alt="Rogue.Win32.InternetSecurityGuard" width="400" height="225" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.InternetSecurityGuard_4.png"><img class="alignnone size-medium wp-image-2783" title="Rogue.Win32.InternetSecurityGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.InternetSecurityGuard_4-400x303.png" alt="Rogue.Win32.InternetSecurityGuard" width="400" height="303" /></a></p>
<p>To register and uninstall this rogue application, you can try one of the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>K7LY-R5GU-SI9D-EVFB</strong>
<strong>K7LY-H4KA-SI9D-U2FD</strong>
<strong>U2FD-S2LA-H4KA-UEPB</strong></span></pre>
<p><strong>How to remove the infection of Internet Security Guard </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.InternetSecurityGuard" target="_blank">Rogue.Win32.InternetSecurityGuard</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Smart Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/12/26/home-security-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Home Security Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/08/guard-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Guard Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/03/22/cleanup-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">CleanUP Antivirus Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>System Check Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/01/02/system-check-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/01/02/system-check-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 02 Jan 2012 06:46:47 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAlert]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[System Check]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2772</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the System Check rogue. Emsisoft Anti-Malware detects this malware as Rogue.Win32.SystemCheck. System Check is a rogue application, another variant of System Fix, System Restore, Data Restore, Data Recovery, System Recovery, Master Utilities, PC Repair, HDD Repair and System Repair. A rogue application tries to [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>System Check </strong>rogue. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.SystemCheck" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemCheck" target="_blank"><strong>Rogue.Win32.SystemCheck</strong></a><strong>.</strong></p>
<p><strong>System Check </strong>is              a                                          rogue                      application, another variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFix" target="_blank"><strong>System Fix</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRestore" target="_blank"><strong>System Restore</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataRestore"><strong>Data Restore</strong></a>, <strong><a title="Adware.Win32.DataRecovery" href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataRecovery" target="_blank">Data Recovery</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRecovery"><strong>System Recovery</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MasterUtilities"><strong>Master Utilities</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PCRepair"><strong>PC Repair</strong></a><strong>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDRepair"><strong>HDD Repair</strong></a> and <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRepair"><strong>System Repair</strong></a>.     A rogue application tries to trick you by displaying false positive   or   misleading scan results report, which says that your computer has a     problem, or infected with viruses or trojan, but you will not be  able  to   fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\[random].exe</li>
<li>%AllUsersProfile%\Application Data\[random].exe</li>
<li>%AllUsersProfile%\Application Data\~[random]</li>
<li>%AllUsersProfile%\Application Data\~[random]r</li>
<li>%AllUsersProfile%\Application Data\[random]</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\System Check.lnk</li>
<li>%UserProfile%\Desktop\System Check.lnk</li>
<li>%Temp%\3.tmp</li>
<li>%Temp%\smtmp\</li>
<li>%Temp%\smtmp\2\</li>
<li>%Temp%\smtmp\4\</li>
<li>%Temp%\smtmp\1\</li>
<li>%UserProfile%\Start Menu\Programs\System Check\</li>
<li>%UserProfile%\Start Menu\Programs\System Check\Uninstall System Check.lnk</li>
<li>%UserProfile%\Start Menu\Programs\System Check\System Check.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\policies\system\<br />
DisableTaskMgr = 01000000</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run\<br />
[random].exe = %AllUsersProfile%\Application Data\[random].exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Control Panel\<br />
nsreg = F82D014F</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Control Panel\<br />
bin =  43003A005C0044006F006&#8230;</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures = no</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Main\<br />
Use FormSuggest = Yes</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
Hidden = (empty)<br />
ShowSuperHidden = (empty)<br />
TaskbarGlomming = (empty)<br />
TaskbarGlomLevel = 02000000<br />
Start_ShowControlPanel = (empty)</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\<br />
HidNoChangingWallPaperden = 01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Policies\Associations\<br />
LowRiskFileTypess = .zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi; .mpg;.mpeg;.mov;.mp3;.m3u;.wav;.scr;</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Policies\Attachments\<br />
SaveZoneInformation = 01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\softare\Microsoft\Windows\CurrentVersion\Policies\Explorer\<br />
NoDesktop = 01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Policies\System\<br />
DisableTaskMgr = 01000000</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.SystemCheck_1.png"><img class="alignnone size-medium wp-image-2773" title="Rogue.Win32.SystemCheck" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.SystemCheck_1-400x260.png" alt="Rogue.Win32.SystemCheck" width="400" height="260" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.SystemCheck_2.png"><img class="alignnone size-medium wp-image-2774" title="Rogue.Win32.SystemCheck" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.SystemCheck_2-400x260.png" alt="Rogue.Win32.SystemCheck" width="400" height="260" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.SystemCheck_3.png"><img class="alignnone size-medium wp-image-2775" title="Rogue.Win32.SystemCheck" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.SystemCheck_3-400x260.png" alt="Rogue.Win32.SystemCheck" width="400" height="260" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.SystemCheck_4.png"><img class="alignnone size-medium wp-image-2776" title="Rogue.Win32.SystemCheck" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.SystemCheck_4-400x203.png" alt="Rogue.Win32.SystemCheck" width="400" height="203" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number, and enter any email:</p>
<pre><span style="color: #ff0000;"><strong>1203978628012489708290478989147</strong></span>
<strong></strong></pre>
<p><strong>How to remove the infection of System Check</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemCheck" target="_blank">Rogue.Win32.SystemCheck</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/11/15/system-fix-rogue-removal-instructions/" rel="bookmark" class="crp_title">System Fix Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/system-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">System Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/03/data-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/09/15/data-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/09/05/system-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">System Recovery Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/01/02/system-check-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Super AV Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/12/30/super-av-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/12/30/super-av-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 30 Dec 2011 08:30:20 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[SuperAV]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2766</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Super AV. Emsisoft Anti-Malware detects this malware as Rogue.Win32.SuperAV. Super AV is a rogue application, this is another variant of Antivirii 2011. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Super AV</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.SuperAV" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SuperAV" target="_blank"><strong>Rogue.Win32.SuperAV</strong></a><strong>.</strong></p>
<p><strong>Super AV </strong><strong></strong>is                            a                                          rogue                                    application, this is another variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.Antivirii2011" target="_blank"><strong>Antivirii 2011</strong></a>. A rogue application tries to   trick  you     by     displaying false    positive or  misleading scan   results   report,     which  says   that your    computer has a    problem, or  infected  with     viruses or  trojan,   but    you will   not be able to   fix it before    you   purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%SystemDrive%\xhergjui.exe</li>
<li>%SystemRoot%\bgmgfhpi.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run\<br />
Security = %SystemRoot%\bgmgfhpi.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe\<br />
Debugger = %SystemDrive%\xhergjui.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.SuperAV_1.png"><img class="alignnone size-medium wp-image-2767" title="Rogue.Win32.SuperAV" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.SuperAV_1-400x326.png" alt="Rogue.Win32.SuperAV" width="400" height="326" /></a></p>
<p><strong>How to remove the infection of Super AV </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SuperAV" target="_blank">Rogue.Win32.SuperAV</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/12/13/antivirii-2011-rogue-removal-instructions/" rel="bookmark" class="crp_title">Antivirii 2011 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/19/security-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/07/privacy-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Privacy Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/23/internet-security-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/04/13/antivirus-clean-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Clean 2011 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/12/30/super-av-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Home Security Solutions Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/12/26/home-security-solutions-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/12/26/home-security-solutions-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 26 Dec 2011 05:27:44 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Home Security Solutions]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2757</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Home Security Solutions. Emsisoft Anti-Malware detects this malware as Rogue.Win32.HomeSecuritySolutions. Home Security Solutions is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Home Security Solutions</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.HomeSecuritySolutions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.HomeSecuritySolutions" target="_blank"><strong>Rogue.Win32.HomeSecuritySolutions</strong></a><strong>.</strong></p>
<p><strong>Home Security Solutions </strong><strong></strong>is                           a                                          rogue                                   application. A rogue application tries to  trick  you     by     displaying false    positive or  misleading scan  results   report,     which  says   that your    computer has a   problem, or  infected  with     viruses or  trojan,   but    you will  not be able to   fix it before    you   purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\93d79\</li>
<li>%AllUsersProfile%\Application Data\93d79\Quarantine Items\</li>
<li>%AllUsersProfile%\Application Data\93d79\HSSSys\</li>
<li>%AllUsersProfile%\Application Data\93d79\HSS.ico</li>
<li>%AllUsersProfile%\Application Data\93d79\mozcrt19.dll</li>
<li>%AllUsersProfile%\Application Data\93d79\sqlite3.dll</li>
<li>%AllUsersProfile%\Application Data\93d79\HS147.exe</li>
<li>%AllUsersProfile%\Application Data\HSMGPBWS\</li>
<li>%AllUsersProfile%\Application Data\HSMGPBWS\HSVNAS.cfg</li>
<li>%AppData%\Home Security Solutions\</li>
<li>%AppData%\Home Security Solutions\Instructions.ini</li>
<li>%AppData%\Home Security Solutions\ScanDisk_.exe</li>
<li>%AppData%\Home Security Solutions\cookies.sqlite</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\Home Security Solutions.lnk</li>
<li>%UserProfile%\Desktop\Home Security Solutions.lnk</li>
<li>%UserProfile%\Recent\tjd.sys</li>
<li>%UserProfile%\Recent\tjd.tmp</li>
<li>%UserProfile%\Recent\CLSV.exe</li>
<li>%UserProfile%\Recent\delfile.dll</li>
<li>%UserProfile%\Recent\dudl.tmp</li>
<li>%UserProfile%\Recent\eb.sys</li>
<li>%UserProfile%\Recent\energy.sys</li>
<li>%UserProfile%\Recent\exec.exe</li>
<li>%UserProfile%\Recent\exec.tmp</li>
<li>%UserProfile%\Recent\FW.drv</li>
<li>%UserProfile%\Recent\gid.tmp</li>
<li>%UserProfile%\Recent\hymt.sys</li>
<li>%UserProfile%\Recent\kernel32.drv</li>
<li>%UserProfile%\Recent\pal.exe</li>
<li>%UserProfile%\Recent\PE.tmp</li>
<li>%UserProfile%\Recent\SICKBOY.drv</li>
<li>%UserProfile%\Recent\std.dll</li>
<li>%UserProfile%\Start Menu\Home Security Solutions.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Home Security Solutions.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\clsid\{3F2BBC05-40DF-11D2-9455-00104BC936FF}<br />
(Default)  = Implements DocHostUIHandler<br />
LocalServer32  = %AllUsersProfile%\Application Data\93d79\HS147.exe<br />
ProgID  = HS147.DocHostUIHandler</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\HS147.DocHostUIHandler<br />
(Default)  = Implements DocHostUIHandler<br />
Clsid  = {3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cl.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frmwrk32.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\homeav2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init32.exe \<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MalwareRemoval.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ozn695m5.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsAuxs.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsGui.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsSvc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsTray.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PC_Antispyware2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfndr.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PerAvir.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protector.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qh.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quick Heal.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\QuickHealCleaner.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Save.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveArmor.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveDefense.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveKeep.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secure Veteran.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\secureveteran.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Security Center.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SecurityFighter.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\securitysoldier.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smart.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartprotector.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smrtdefp.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftSafeness.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spywarexpguard.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrustWarrior.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\W3asbas.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windll32.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows Police Pro.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpdeluxe.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~1.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~2.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\3</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\<br />
ltTST = 7F3E0000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures = no<br />
RunInvalidSignatures = 01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\<br />
DisallowRun = 01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\<br />
0 = msseces.exe<br />
1 = MSASCui.exe<br />
2 = ekrn.exe<br />
3 = egui.exe<br />
4 = avgnt.exe<br />
5 = avcenter.exe<br />
6 = avscan.exe<br />
7 = avgfrw.exe<br />
8 = avgui.exe<br />
9 = avgtray.exe<br />
10 = avgscanx.exe<br />
11 = avgcfgex.exe<br />
12 = avgemc.exe<br />
13 = avgchsvx.exe<br />
14 = avgcmgr.exe<br />
15 = avgwdsvc.exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\<br />
Home Security Solutions = &#8220;%AllUsersProfile%\Application Data\93d79\HS147.exe&#8221; /s /d</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\RunOnce\<br />
HSS = &#8220;%Temp%\scandsk211d_8016.exe&#8221; /cs:1</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.HomeSecuritySolutions_1.png"><img class="alignnone size-medium wp-image-2758" title="Rogue.Win32.HomeSecuritySolutions" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.HomeSecuritySolutions_1-400x201.png" alt="Rogue.Win32.HomeSecuritySolutions" width="400" height="201" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.HomeSecuritySolutions_2.png"><img class="alignnone size-medium wp-image-2759" title="Rogue.Win32.HomeSecuritySolutions" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.HomeSecuritySolutions_2-400x292.png" alt="Rogue.Win32.HomeSecuritySolutions" width="400" height="292" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.HomeSecuritySolutions_3.png"><img class="alignnone size-medium wp-image-2760" title="Rogue.Win32.HomeSecuritySolutions" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.HomeSecuritySolutions_3-400x292.png" alt="Rogue.Win32.HomeSecuritySolutions" width="400" height="292" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.HomeSecuritySolutions_4.png"><img class="alignnone size-medium wp-image-2761" title="Rogue.Win32.HomeSecuritySolutions" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.HomeSecuritySolutions_4-400x293.png" alt="Rogue.Win32.HomeSecuritySolutions" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.HomeSecuritySolutions_5.png"><img class="alignnone size-medium wp-image-2762" title="Rogue.Win32.HomeSecuritySolutions" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.HomeSecuritySolutions_5-400x225.png" alt="Rogue.Win32.HomeSecuritySolutions" width="400" height="225" /></a></p>
<p>To register and uninstall this rogue application, you can try one of the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>K7LY-R5GU-SI9D-EVFB</strong></span>
<span style="color: #ff0000;"><strong>K7LY-H4KA-SI9D-U2FD</strong></span>
<span style="color: #ff0000;"><strong>U2FD-S2LA-H4KA-UEPB</strong></span></pre>
<p><strong>How to remove the infection of Home Security Solutions </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HomeSecuritySolutions" target="_blank">Rogue.Win32.HomeSecuritySolutions</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Smart Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/03/22/cleanup-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">CleanUP Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/01/08/guard-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Guard Pro Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/12/26/home-security-solutions-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Monitor 2012 Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/12/14/security-monitor-2012-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/12/14/security-monitor-2012-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 14 Dec 2011 13:45:10 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Security Monitor 2012]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2748</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Security Monitor 2012. Emsisoft Anti-Malware detects this malware as Rogue.Win32.SecurityMonitor2012. Security Monitor 2012 is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Security Monitor 2012</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.SecurityMonitor2012" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecurityMonitor2012" target="_blank"><strong>Rogue.Win32.SecurityMonitor2012</strong></a><strong>.</strong></p>
<p><strong>Security Monitor 2012 </strong><strong> </strong>is                          a                                          rogue                                  application. A rogue application tries to trick  you     by     displaying false    positive or  misleading scan results   report,     which  says   that your    computer has a  problem, or  infected  with     viruses or  trojan,   but    you will not be able to   fix it before    you   purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\Security Monitor.lnk</li>
<li>%AppData%\Security Monitor\</li>
<li>%AppData%\Security Monitor\IcoHelp.ico</li>
<li>%AppData%\Security Monitor\IcoUninstall.ico</li>
<li>%AppData%\Security Monitor\Security Monitor.exe</li>
<li>%AppData%\Security Monitor\securityhelper.exe</li>
<li>%AppData%\Security Monitor\securitymanager.exe</li>
<li>%AppData%\Security Monitor\IcoActivate.ico</li>
<li>%UserProfile%\Desktop\Security Monitor.lnk</li>
<li>%Temp%\aqfitrlxi2.exe</li>
<li>%Temp%\backd-efq.exe</li>
<li>%Temp%\brdss.exe</li>
<li>%Temp%\bzqa43d.exe</li>
<li>%Temp%\cffd4.exe</li>
<li>%Temp%\cocksucker.exe</li>
<li>%Temp%\cosock.exe</li>
<li>%Temp%\cowceb.exe</li>
<li>%Temp%\cunifuc.exe</li>
<li>%Temp%\d20mes.exe</li>
<li>%Temp%\dc_3.exe</li>
<li>%Temp%\dd10x10.exe</li>
<li>%Temp%\ddoll3342.exe</li>
<li>%Temp%\destroyer.exe</li>
<li>%Temp%\dffuck.exe</li>
<li>%Temp%\dkfjd93.exe</li>
<li>%Temp%\ds7hw.exe</li>
<li>%Temp%\eelnvd13.exe</li>
<li>%Temp%\exppdf_w.exe</li>
<li>%Temp%\fadz43.exe</li>
<li>%Temp%\fe.exe</li>
<li>%Temp%\format.exe</li>
<li>%Temp%\g_dx234.exe</li>
<li>%Temp%\ggwwef9752.exe</li>
<li>%Temp%\gpupz2a.exe</li>
<li>%Temp%\hhbboll_2.exe</li>
<li>%Temp%\hiphop.exe</li>
<li>%Temp%\hodeme.exe</li>
<li>%Temp%\htfad4.exe</li>
<li>%Temp%\hvipws9.exe</li>
<li>%Temp%\jdhellwo3.exe</li>
<li>%Temp%\jkfuckfu.exe</li>
<li>%Temp%\jofcdks.exe</li>
<li>%Temp%\kjdh_gf_jjdhgd.exe</li>
<li>%Temp%\kjh102k3.exe</li>
<li>%Temp%\kn.a.exe</li>
<li>%Temp%\kock.exe</li>
<li>%Temp%\ljts-23.exe</li>
<li>%Temp%\lkhgg_ea.exe</li>
<li>%Temp%\lols.exe</li>
<li>%Temp%\ploper.exe</li>
<li>%Temp%\poertd.exe</li>
<li>%Temp%\ppddfcfux.exxe</li>
<li>%Temp%\protector2.exe</li>
<li>%Temp%\pswwg3c.exe</li>
<li>%Temp%\puzpup.exe</li>
<li>%Temp%\qwedvor.exe</li>
<li>%Temp%\qwklrvjhqlkj.exe</li>
<li>%Temp%\r0life.exe</li>
<li>%Temp%\rator.exe</li>
<li>%Temp%\rtfme.exe</li>
<li>%Temp%\safe.exe</li>
<li>%Temp%\snowif.exe</li>
<li>%Temp%\sycre.exe</li>
<li>%Temp%\timem.exe</li>
<li>%Temp%\tryh-blv.exe</li>
<li>%Temp%\w32-reno-c.exe</li>
<li>%Temp%\w32rim_mem.exe</li>
<li>%Temp%\warsddd_w.exe</li>
<li>%Temp%\wefgetn_00.exe</li>
<li>%Temp%\wined.exe</li>
<li>%Temp%\winifi.exe</li>
<li>%Temp%\wrcud12.exe</li>
<li>%Temp%\wrfwe_di.exe</li>
<li>%Temp%\wwautrsd.exe</li>
<li>%Temp%\wwwsssgen.exe</li>
<li>%Temp%\_2.tmp</li>
<li>%Temp%\1iowieoo.exe</li>
<li>%Temp%\02c9c3c35bdx5.exe</li>
<li>%Temp%\8gmsed-bd.exe</li>
<li>%Temp%\17dkf.exe</li>
<li>%Temp%\472a10e2ebxd9.exe</li>
<li>%Temp%\56493.exe</li>
<li>%Temp%\ae0965a7157cd.exe</li>
<li>%Temp%\al3erfa3.exe</li>
<li>%Temp%\alerfa.exe</li>
<li>%Temp%\alerfa2.exe</li>
<li>%Temp%\altedf.exe</li>
<li>%UserProfile%\Start Menu\Programs\Security Monitor.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Security Monitor\</li>
<li>%UserProfile%\Start Menu\Programs\Security Monitor\Help Security Monitor.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Security Monitor\How to Activate Security Monitor.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Security Monitor\Security Monitor.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Security Monitor\Activate Security Monitor.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\<br />
Security Monitor = &#8220;%AppData%\Security Monitor\Security Monitor.exe&#8221; /STARTUP<br />
Security Monitor 2012 Security = %AppData%\Security Monitor\securitymanager.exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Uninstall\Security Monitor\<br />
DisplayName = Security Monitor<br />
UninstallString = &#8220;%AppData%\Security Monitor\securityhelper.exe&#8221; /UNINSTALL<br />
DisplayIcon = &#8220;%AppData%\Security Monitor\securityhelper.exe&#8221;,1</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Security Monitor\<br />
(Default)  = %AppData%\Security Monitor<br />
BuyUrl = B65B17E3F9DA41446905D3BE0E550632B225D0DB132371E38F96D84D2B2F05B40CF125&#8230;<br />
uninstaller = %AppData%\Security Monitor\securityhelper.exe<br />
ADVid = 390<br />
InstallDir = %AppData%\Security Monitor\<br />
SoftID = Security Monitor<br />
ScanSystemOnStartup = 01000000<br />
AutomaticallyUpdates = 01000000<br />
BackgroundScan = 01000000<br />
BackgroundScanTimeout = 01000000<br />
tb = DB070C0003000E000D00090015002202<br />
InstNM =%AppData%\Security Monitor\Security Monitor.exe<br />
LastTimeStamp = FD000000<br />
LastUpdateDate = 2011/11/23</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.SecurityMonitor2012_1.png"><img class="alignnone size-medium wp-image-2749" title="Rogue.Win32.SecurityMonitor2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.SecurityMonitor2012_1-400x319.png" alt="Rogue.Win32.SecurityMonitor2012" width="400" height="319" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.SecurityMonitor2012_2.png"><img class="alignnone size-medium wp-image-2750" title="Rogue.Win32.SecurityMonitor2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.SecurityMonitor2012_2-400x315.png" alt="Rogue.Win32.SecurityMonitor2012" width="400" height="315" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.SecurityMonitor2012_3.png"><img class="alignnone size-medium wp-image-2751" title="Rogue.Win32.SecurityMonitor2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.SecurityMonitor2012_3-400x358.png" alt="Rogue.Win32.SecurityMonitor2012" width="400" height="358" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.SecurityMonitor2012_4.png"><img class="alignnone size-medium wp-image-2752" title="Rogue.Win32.SecurityMonitor2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.SecurityMonitor2012_4-400x211.png" alt="Rogue.Win32.SecurityMonitor2012" width="400" height="211" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.SecurityMonitor2012_5.png"><img class="alignnone size-medium wp-image-2753" title="Rogue.Win32.SecurityMonitor2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.SecurityMonitor2012_5-400x371.png" alt="Rogue.Win32.SecurityMonitor2012" width="400" height="371" /></a></strong></p>
<p><strong>How to remove the infection of Security Monitor 2012 </strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecurityMonitor2012" target="_blank">Rogue.Win32.SecurityMonitor2012</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/10/09/antivirus-studio-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">AntiVirus Studio 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">System Security 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/23/av-protection-2011-rogue-removal-instructions/" rel="bookmark" class="crp_title">AV Protection 2011 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/cloud-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Cloud Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/06/security-guard-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Guard 2012 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/12/14/security-monitor-2012-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>XP Antivirus 2012 (MultiFakeAV) Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/11/29/xp-antivirus-2012-multifakeav-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/11/29/xp-antivirus-2012-multifakeav-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 29 Nov 2011 13:51:44 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Fake Rean]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Win 7 Antispyware 2012]]></category>
		<category><![CDATA[Win32]]></category>
		<category><![CDATA[XP Antivirus 2012]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2735</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the XP Antivirus 2012 (MultiFakeAV). Emsisoft Anti-Malware detects this malware as Rogue.Win32.MultiFakeAV. XP Antivirus 2012 is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>XP Antivirus 2012</strong> (MultiFakeAV). <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.MultiFakeAV" href="http://www.emsisoft.com/en/malware/?Adware.Win32.MultiFakeAV" target="_blank"><strong>Rogue.Win32.MultiFakeAV</strong></a><strong>.</strong></p>
<p><strong>XP Antivirus 2012 </strong><strong></strong>is                         a                                          rogue                                 application. A rogue application tries to trick  you    by     displaying false    positive or  misleading scan results  report,     which  says   that your    computer has a  problem, or infected  with     viruses or  trojan,   but    you will not be able to  fix it before    you   purchase. This rogue scanner program able to change their name depend on the operating system, on Windows 7 for example, the name is &#8220;<strong>Win 7 Antispyware 2012</strong>&#8220;.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\157850g1p046c522p184r5dtv4q8</li>
<li>%AppData%\157850g1p046c522p184r5dtv4q8</li>
<li>%Temp%\157850g1p046c522p184r5dtv4q8</li>
<li>%UserProfile%\Templates\157850g1p046c522p184r5dtv4q8</li>
<li>%UserProfile%\Local Settings\Application Data\%random%.exe</li>
</ul>
<p><strong>Create/modify new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\<br />
command  = &#8220;%UserProfile%\Local Settings\Application Data\%random%.exe&#8221; -a &#8220;C:\Program Files\Mozilla Firefox\firefox.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\<br />
command  = &#8220;%UserProfile%\Local Settings\Application Data\%random%.exe&#8221; -a &#8220;C:\Program Files\Mozilla Firefox\firefox.exe&#8221; -safe-mode</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\<br />
command  = &#8220;%UserProfile%\Local Settings\Application Data\%random%.exe&#8221; -a &#8220;C:\Program Files\Internet Explorer\iexplore.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_CLASSES_ROOT\.exe<br />
(Default) = exefile</li>
</ul>
<ul>
<li>HKEY_CLASSES_ROOT\.exe\<br />
Content Type = application/x-msdownload<br />
DefaultIcon  = %1</li>
</ul>
<ul>
<li>HKEY_CLASSES_ROOT\.exe\shell\open\command<br />
(Default) = &#8220;%UserProfile%\Local Settings\Application Data\%random%.exe&#8221; -a &#8220;%1&#8243; %*<br />
IsolatedCommand = &#8220;%1&#8243; %*</li>
</ul>
<ul>
<li>HKEY_CLASSES_ROOT\.exe\shell\runas\command<br />
(Default) = &#8220;%1&#8243; %*<br />
IsolatedCommand = &#8220;%1&#8243; %*</li>
</ul>
<ul>
<li>HKEY_CLASSES_ROOT\exefile<br />
(Default) = Application<br />
Content Type = application/x-msdownload<br />
DefaultIcon  = %1</li>
</ul>
<ul>
<li>HKEY_CLASSES_ROOT\exefile\shell\open\command<br />
(Default) = &#8220;%UserProfile%\Local Settings\Application Data\%random%.exe&#8221; -a &#8220;%1&#8243; %*<br />
IsolatedCommand = &#8220;%1&#8243; %*</li>
</ul>
<ul>
<li>HKEY_CLASSES_ROOT\exefile\shell\runas\command<br />
(Default) = &#8220;%1&#8243; %*<br />
IsolatedCommand = &#8220;%1&#8243; %*</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.MultiFakeAV_1.png"><img class="alignnone size-medium wp-image-2736" title="Rogue.Win32.MultiFakeAV" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.MultiFakeAV_1-400x281.png" alt="Rogue.Win32.MultiFakeAV" width="400" height="281" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.MultiFakeAV_6.png"><img class="alignnone size-medium wp-image-2737" title="Rogue.Win32.MultiFakeAV" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.MultiFakeAV_6-400x285.png" alt="Rogue.Win32.MultiFakeAV" width="400" height="285" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>3425-814615-3990</strong></span></pre>
<p><strong>How to remove the infection of XP Antivirus 2012 (MultiFakeAV) </strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MultiFakeAV" target="_blank">Rogue.Win32.MultiFakeAV</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/08/19/xp-home-security-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">XP Home Security 2012 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/22/xp-antispyware-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">XP AntiSpyware 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/11/23/win-7-antispyware-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">Win 7 Antispyware 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/09/xp-antivirus-pro-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">XP Antivirus Pro 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/28/win-antispyware-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Win Antispyware Center Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/11/29/xp-antivirus-2012-multifakeav-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cloud AV 2012 Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/11/25/cloud-av-2012-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/11/25/cloud-av-2012-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 25 Nov 2011 06:54:00 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Cloud AV 2012]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2729</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Cloud AV 2012. Emsisoft Anti-Malware detects this malware as Rogue.Win32.CloudAV2012. Cloud AV 2011 is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Cloud AV 2012</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.CloudAV2012" href="http://www.emsisoft.com/en/malware/?Adware.Win32.CloudAV2012" target="_blank"><strong>Rogue.Win32.CloudAV2012</strong></a><strong>.</strong></p>
<p><strong>Cloud AV 2011 </strong><strong> </strong>is                        a                                          rogue                                application. A rogue application tries to trick  you    by    displaying false    positive or  misleading scan results  report,    which  says   that your    computer has a  problem, or infected  with    viruses or  trojan,   but    you will not be able to  fix it before   you   purchase.</p>
<p><strong>The following is another variant of AV Protection 2011:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVProtection2011" target="_blank"><strong>AV Protection 2011</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVSecurity2012" target="_blank"><strong>AV Security 2012</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemSecurity2011">System Security 2011</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVProtectionOnline" target="_blank">AV Protection Online</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardOnline"><strong>Guard Online</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.CloudProtection"><strong>Cloud Protection</strong></a></li>
</ul>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\4DA54\</li>
<li>%ProgramFiles%\4DA54\lvvm.exe</li>
<li>%ProgramFiles%\LP\</li>
<li>%ProgramFiles%\LP\41F5\</li>
<li>%ProgramFiles%\LP\41F5\9.tmp</li>
<li>%ProgramFiles%\LP\41F5\18.tmp</li>
<li>%ProgramFiles%\LP\41F5\A.tmp</li>
<li>%ProgramFiles%\LP\41F5\C29.exe</li>
<li>%SystemRoot%\system32\Cloud AV 2012v121.exe</li>
<li>%AppData%\ahst.lni</li>
<li>%AppData%\dwme.exe</li>
<li>%AppData%\50C4D\</li>
<li>%AppData%\50C4D\57741.exe</li>
<li>%AppData%\50C4D\DA54.0C4</li>
<li>%AppData%\z8gTZqhYCkVlNx0\</li>
<li>%AppData%\DaQH6sWK7R9TqUe\</li>
<li>%AppData%\uS2ibF3pn5Q6W8R\</li>
<li>%AppData%\XZqjYCekIr\</li>
<li>%UserProfile%\Desktop\Cloud AV 2012.lnk</li>
<li>%Temp%\8.tmp</li>
<li>%Temp%\dwme.exe</li>
<li>%UserProfile%\Start Menu\Programs\Cloud AV 2012\</li>
<li>%UserProfile%\Start Menu\Programs\Cloud AV 2012\Cloud AV 2012.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run\<br />
fgRZ9hYXwUeOtPy8234A = %SystemRoot%\system32\Cloud AV 2012v121.exe<br />
pIBrzPNyx1v2b4m = %AppData%\dwme.exe<br />
C29.exe = %ProgramFiles%\LP\41F5\C29.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\wscsvc\<br />
Start = 0&#215;00000003</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon\<br />
Shell = explorer.exe,%AppData%\50C4D\57741.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.CloudAV2012_1.png"><img class="alignnone size-medium wp-image-2730" title="Rogue.Win32.CloudAV2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.CloudAV2012_1-400x255.png" alt="Rogue.Win32.CloudAV2012" width="400" height="255" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.CloudAV2012_2.png"><img class="alignnone size-medium wp-image-2731" title="Rogue.Win32.CloudAV2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.CloudAV2012_2-400x330.png" alt="Rogue.Win32.CloudAV2012" width="400" height="330" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.CloudAV2012_3.png"><img class="alignnone size-medium wp-image-2732" title="Rogue.Win32.CloudAV2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.CloudAV2012_3-400x248.png" alt="Rogue.Win32.CloudAV2012" width="400" height="248" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>9992665263</strong></span></pre>
<p><strong>How to remove the infection of Cloud AV 2012 </strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.CloudAV2012" target="_blank">Rogue.Win32.CloudAV2012</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/11/23/av-protection-2011-rogue-removal-instructions/" rel="bookmark" class="crp_title">AV Protection 2011 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Security 2012 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/cloud-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Cloud Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">System Security 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/19/av-protection-online-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Protection Online Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/11/25/cloud-av-2012-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AV Protection 2011 Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/11/23/av-protection-2011-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/11/23/av-protection-2011-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 23 Nov 2011 16:48:57 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[AV Protection 2011]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2720</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the AV Protection 2011. Emsisoft Anti-Malware detects this malware as Rogue.Win32.AVProtection2011. AV Protection 2011 is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>AV Protection 2011</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.AVProtection2011" href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVProtection2011" target="_blank"><strong>Rogue.Win32.AVProtection2011</strong></a><strong>.</strong></p>
<p><strong>AV Protection 2011 </strong><strong></strong>is                       a                                          rogue                               application. A rogue application tries to trick  you   by    displaying false    positive or  misleading scan results  report,   which  says   that your    computer has a  problem, or infected  with   viruses or  trojan,   but    you will not be able to  fix it before  you   purchase.</p>
<p>The following is another variant of AV Protection 2011:</p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVSecurity2012" target="_blank"><strong>AV Security 2012</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemSecurity2011">System Security 2011</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVProtectionOnline" target="_blank">AV Protection Online</a>,</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardOnline"><strong>Guard Online</strong></a>,<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.CloudProtection"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.CloudProtection"><strong>Cloud Protection</strong></a>.</li>
</ul>
<p><strong>Create new files and folders:</strong></p>
<ul>
<li>%ProgramFiles%\4DA54\</li>
<li>%ProgramFiles%\4DA54\lvvm.exe</li>
<li>%ProgramFiles%\LP\</li>
<li>%ProgramFiles%\LP\41F5\</li>
<li>%ProgramFiles%\LP\41F5\17.tmp</li>
<li>%ProgramFiles%\LP\41F5\18.tmp</li>
<li>%ProgramFiles%\LP\41F5\19.tmp</li>
<li>%ProgramFiles%\LP\41F5\C29.exe</li>
<li>%SystemRoot%\system32\AV Protection 2011v121.exe</li>
<li>%AppData%\dwme.exe</li>
<li>%AppData%\ldr.ini</li>
<li>%AppData%\50C4D\</li>
<li>%AppData%\50C4D\DA54.0C4</li>
<li>%AppData%\50C4D\57741.exe</li>
<li>%AppData%\fJ6dEK8fR9YwUeO\</li>
<li>%AppData%\gkIVrlONtAuSiFp\</li>
<li>%AppData%\hP0ycS1iv3n4m6W\</li>
<li>%AppData%\XP0ucS1ib3n4Q6W\</li>
<li>%UserProfile%\Desktop\AV Protection 2011.lnk</li>
<li>%Temp%\dwme.exe</li>
<li>%Temp%\1A.tmp</li>
<li>%Temp%\16.tmp</li>
<li>%UserProfile%\Start Menu\Programs\AV Protection 2011\</li>
<li>%UserProfile%\Start Menu\Programs\AV Protection 2011\AV Protection 2011.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run\<br />
jD2onF4pm5W7E8T8234A = %SystemRoot%\system32\AV Protection 2011v121.exe<br />
AG5aQJ6dW8R9TwU = %AppData%\dwme.exe<br />
C29.exe = %ProgramFiles%\LP\41F5\C29.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\wscsvc\<br />
Start = 03000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon\<br />
Shell = explorer.exe,%AppData%\50C4D\57741.exe</li>
</ul>
<p>Screenshots:</p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.AVProtection2011_1.png"><img class="alignnone size-medium wp-image-2721" title="Rogue.Win32.AVProtection2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.AVProtection2011_1-400x255.png" alt="Rogue.Win32.AVProtection2011" width="400" height="255" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.AVProtection2011_2.png"><img class="alignnone size-medium wp-image-2722" title="Rogue.Win32.AVProtection2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.AVProtection2011_2-400x330.png" alt="Rogue.Win32.AVProtection2011" width="400" height="330" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.AVProtection2011_3.png"><img class="alignnone size-medium wp-image-2723" title="Rogue.Win32.AVProtection2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.AVProtection2011_3-400x248.png" alt="Rogue.Win32.AVProtection2011" width="400" height="248" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>9992665263</strong></span></pre>
<p><strong>How to remove the infection of AV Protection 2011 </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVProtection2011" target="_blank">Rogue.Win32.AVProtection2011</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/11/25/cloud-av-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Cloud AV 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/19/av-protection-online-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Protection Online Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/cloud-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Cloud Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">System Security 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Security 2012 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/11/23/av-protection-2011-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>System Fix Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/11/15/system-fix-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/11/15/system-fix-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 15 Nov 2011 09:31:34 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[System Fix]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2713</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the System Fix rogue. Emsisoft Anti-Malware detects this malware as Rogue.Win32.SystemFix. System Fix is a rogue application, another variant of System Restore, Data Restore, Data Recovery, System Recovery, Master Utilities, PC Repair, HDD Repair and System Repair. A rogue application tries to trick you [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>System Fix </strong>rogue. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.SystemFix" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFix" target="_blank"><strong>Rogue.Win32.SystemFix</strong></a><strong>.</strong></p>
<p><strong>System Fix </strong><strong> </strong>is              a                                          rogue                      application, another variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRestore" target="_blank"><strong>System Restore</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataRestore"><strong>Data Restore</strong></a>, <strong><a title="Adware.Win32.DataRecovery" href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataRecovery" target="_blank">Data Recovery</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRecovery"><strong>System Recovery</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MasterUtilities"><strong>Master Utilities</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PCRepair"><strong>PC Repair</strong></a><strong>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDRepair"><strong>HDD Repair</strong></a> and <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRepair"><strong>System Repair</strong></a>.    A rogue application tries to trick you by displaying false positive  or   misleading scan results report, which says that your computer has a    problem, or infected with viruses or trojan, but you will not be able  to   fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfiles%\Application Data\[random]</li>
<li>%AllUsersProfiles%\Application Data\[random].exe</li>
<li>%AllUsersProfiles%\Application Data\[random].exe</li>
<li>%AllUsersProfiles%\Application Data\~[random]</li>
<li>%AllUsersProfiles%\Application Data\~[random]</li>
<li>%AllUsersProfiles%\Local Settings\Temp\37dbffa0005fc824.exe</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk</li>
<li>%UserProfile%\Desktop\System Fix.lnk</li>
<li>%Temp%\36.tmp</li>
<li>%Temp%\ulN4aaevqp3o76.exe.tmp</li>
<li>%Temp%\smtmp\</li>
<li>%Temp%\smtmp\1\</li>
<li>%Temp%\smtmp\2\</li>
<li>%Temp%\smtmp\4\</li>
<li>%UserProfile%\Start Menu\Programs\System Fix\</li>
<li>%UserProfile%\Start Menu\Programs\System Fix\System Fix.lnk</li>
<li>%UserProfile%\Start Menu\Programs\System Fix\Uninstall System Fix.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\Explorer\Run\<br />
[random]: %AllUsersProfiles%\Local Settings\Temp\37dbffa0005fc824.exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Control Panel\<br />
nsreg: 0010C24E<br />
bin: 43003A005C0044006F00630075006D006500&#8230;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\<br />
DisableTaskMgr: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\<br />
75fa38b7-8b94-4995-ad32-52e938867954:<br />
BD: 43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 74 00 73 00 20 00 61 00…</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\<br />
Use FormSuggest: “Yes”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\<br />
WarnonBadCertRecving: 0×00000000<br />
CertificateRevocation: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\<br />
NoChangingWallPaper: 0×00000001<br />
HidNoChangingWallPaperden: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\<br />
NoDesktop: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\<br />
LowRiskFileTypes:          “.zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;<br />
.mp3;.m3u;.wav;.scr;”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\<br />
SaveZoneInformation: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
%random%: “%AllUsersProfile%\Application Data\%random%.exe”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures: “no”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
Hidden: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
ShowSuperHidden: 0×00000000</li>
</ul>
<p><strong>HTTP Requests:</strong></p>
<ul>
<li>ld2repgnifnmgfk.com</li>
<li>85.121.39.27</li>
<li>galaxyadvanta.com</li>
<li>pubidviseron.com</li>
<li>subishiphil.com</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.SystemFix_1.png"><img class="alignnone size-medium wp-image-2714" title="Rogue.Win32.SystemFix" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.SystemFix_1-400x260.png" alt="Rogue.Win32.SystemFix" width="400" height="260" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.SystemFix_2.png"><img class="alignnone size-medium wp-image-2715" title="Rogue.Win32.SystemFix" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.SystemFix_2-400x260.png" alt="Rogue.Win32.SystemFix" width="400" height="260" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.SystemFix_3.png"><img class="alignnone size-medium wp-image-2716" title="Rogue.Win32.SystemFix" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.SystemFix_3-400x260.png" alt="Rogue.Win32.SystemFix" width="400" height="260" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number, and enter any email:</p>
<pre><span style="color: #ff0000;"><strong>1203978628012489708290478989147</strong></span>
<strong></strong></pre>
<p><strong>How to remove the infection of System Fix</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFix" target="_blank">Rogue.Win32.SystemFix</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/10/03/data-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/system-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">System Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/09/15/data-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/09/05/system-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">System Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/02/system-check-rogue-removal-instructions/" rel="bookmark" class="crp_title">System Check Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/11/15/system-fix-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AV Security 2012 Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 10 Nov 2011 13:05:24 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[AV Security 2012]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2708</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the AV Security 2012. Emsisoft Anti-Malware detects this malware as Adware.Win32.AVSecurity2012. AV Security 2012 is a rogue application. This is another variant of System Security 2011, AV Protection Online, Guard Online and Cloud Protection. A rogue application tries to trick you by displaying false [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>AV Security 2012</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.AVSecurity2012" href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVSecurity2012" target="_blank"><strong>Adware.Win32.AVSecurity2012</strong></a><strong>.</strong></p>
<p><strong>AV Security 2012 </strong><strong></strong>is                      a                                          rogue                              application.  This is another variant of <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemSecurity2011">System Security 2011</a>,</strong> <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVProtectionOnline" target="_blank">AV Protection Online</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardOnline"><strong>Guard Online</strong></a> and <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.CloudProtection"><strong>Cloud Protection</strong></a>.   A rogue application tries to trick  you   by    displaying false   positive or  misleading scan results  report,   which  says   that your   computer has a  problem, or infected  with   viruses or  trojan,   but   you will not be able to  fix it before  you   purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%SystemRoot%\system32\AV Security 2012v121.exe</li>
<li> %AppData%\ldr.ini</li>
<li> %AppData%\[random]\</li>
<li> %AppData%\[random]\</li>
<li> %AppData%\[random]\AV Security 2012.ico</li>
<li> %AppData%\[random]\</li>
<li> %UserProfile%\Desktop\AV Security 2012.lnk</li>
<li> %UserProfile%\Local Settings\Temp\B.tmp</li>
<li> %UserProfile%\Start Menu\Programs\AV Security 2012\</li>
<li>%UserProfile%\Start Menu\Programs\AV Security 2012\AV Security 2012.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run<br />
&#8220;[random]=%SystemRoot%\system32\AV Security 2012v121.exe&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.AVSecurity2012_1.png"><img class="alignnone size-medium wp-image-2709" title="Adware.Win32.AVSecurity2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.AVSecurity2012_1-400x255.png" alt="Adware.Win32.AVSecurity2012" width="400" height="255" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.AVSecurity2012_2.png"><img class="alignnone size-medium wp-image-2710" title="Adware.Win32.AVSecurity2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.AVSecurity2012_2-400x334.png" alt="Adware.Win32.AVSecurity2012" width="400" height="334" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.AVSecurity2012_3.png"><img class="alignnone size-medium wp-image-2711" title="Adware.Win32.AVSecurity2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.AVSecurity2012_3-400x251.png" alt="Adware.Win32.AVSecurity2012" width="400" height="251" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>9992665263</strong></span></pre>
<p><strong>How to remove the infection of AV Security 2012</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVSecurity2012" target="_blank">Adware.Win32.AVSecurity2012</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/11/25/cloud-av-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Cloud AV 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/06/security-guard-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Guard 2012 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/23/av-protection-2011-rogue-removal-instructions/" rel="bookmark" class="crp_title">AV Protection 2011 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">System Security 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/19/av-protection-online-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Protection Online Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Privacy Protection Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/11/07/privacy-protection-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/11/07/privacy-protection-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 07 Nov 2011 09:23:52 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Privacy Protection]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2701</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Privacy Protection. Emsisoft Anti-Malware detects this malware as Adware.Win32.PrivacyProtection. Privacy Protection is a rogue application.  A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Privacy Protection</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.PrivacyProtection" href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyProtection" target="_blank"><strong>Adware.Win32.PrivacyProtection</strong></a><strong>.</strong></p>
<p><strong>Privacy Protection </strong><strong></strong>is                      a                                          rogue                              application.   A rogue application tries to trick  you   by    displaying false   positive or  misleading scan results  report,   which  says   that your   computer has a  problem, or infected  with   viruses or  trojan,   but   you will not be able to  fix it before  you   purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li> %AllUsersProfiles%\Application Data\privacy.exe</li>
<li> %AllUsersProfiles%\Desktop\Privacy Protection.lnk</li>
<li>%Temp%\6C.tmp</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\EFF9375FC10561A906A809B93DD5038F<br />
FRun=&#8221;0&#8243;<br />
O`ld=&#8221;Qshw`bx!Qsnudbuhno&#8221;<br />
Q`ui=&#8221;B;]Enbtldour!`oe!Rduuhofr]@mm!Trdsr]@qqmhb`uhno!E&#8230;&#8221;</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER|\Software\Microsoft\Windows\CurrentVersion\Run<br />
Privacy Protection = %AllUsersProfiles%\Application Data\privacy.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.PrivacyProtection.png"><img class="alignnone size-medium wp-image-2705" title="Adware.Win32.PrivacyProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.PrivacyProtection-400x294.png" alt="Adware.Win32.PrivacyProtection" width="400" height="294" /></a></p>
<p><strong>How to remove the infection of Privacy Protection</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyProtection" target="_blank">Adware.Win32.PrivacyProtection</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/08/19/security-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/23/smart-protection-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Smart Protection 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/03/security-sphere-2012-removal-instructions/" rel="bookmark" class="crp_title">Security Sphere 2012 Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/10/protection-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Protection Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/19/av-protection-online-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Protection Online Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/11/07/privacy-protection-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>System Security 2011 Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 24 Oct 2011 02:57:03 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[System Security 2011]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2694</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the System Security 2011. Emsisoft Anti-Malware detects this malware as Adware.Win32.SystemSecurity2011. System Security 2011 is a rogue application. This is another variant of AV Protection Online, Guard Online and Cloud Protection. A rogue application tries to trick you by displaying false positive or misleading [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>System Security 2011</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.SystemSecurity2011" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemSecurity2011" target="_blank"><strong>Adware.Win32.SystemSecurity2011</strong></a><strong>.</strong></p>
<p><strong>System Security 2011 </strong><strong></strong>is                     a                                          rogue                             application.  This is another variant of <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVProtectionOnline" target="_blank">AV Protection Online</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardOnline"><strong>Guard Online</strong></a> and <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.CloudProtection"><strong>Cloud Protection</strong></a>.  A rogue application tries to trick  you   by    displaying false  positive or  misleading scan results  report,   which  says   that your  computer has a  problem, or infected  with   viruses or  trojan,   but  you will not be able to  fix it before  you   purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%SystemRoot%\system32\[random].exe</li>
<li>%AppData%\ldr.ini</li>
<li>%AppData%\svhostu.exe</li>
<li>%AppData%\[random]\</li>
<li>%AppData%\[random]\</li>
<li>%AppData%\[random]\</li>
<li>%AppData%\[random]\System Security  2011.ico</li>
<li>%AppData%\[random]\</li>
<li>%UserProfile%\Desktop\System Security  2011.lnk</li>
<li>%UserProfile%\Local Settings\Temp\B.tmp</li>
<li>%UserProfile%\Local Settings\Temp\svhostu.exe</li>
<li>%UserProfile%\Start Menu\Programs\System Security  2011\</li>
<li>%UserProfile%\Start Menu\Programs\System Security  2011\System Security  2011.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run\<br />
(String) [random] = %SystemRoot%\system32\[random].exe<br />
(String) [random] = %AppData%\svhostu.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemSecurity2011_1.png"><img class="alignnone size-medium wp-image-2695" title="Adware.Win32.SystemSecurity2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemSecurity2011_1-400x255.png" alt="Adware.Win32.SystemSecurity2011" width="400" height="255" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemSecurity2011_2.png"><img class="alignnone size-medium wp-image-2696" title="Adware.Win32.SystemSecurity2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemSecurity2011_2-400x334.png" alt="Adware.Win32.SystemSecurity2011" width="400" height="334" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemSecurity2011_3.png"><img class="alignnone size-medium wp-image-2697" title="Adware.Win32.SystemSecurity2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemSecurity2011_3-400x251.png" alt="Adware.Win32.SystemSecurity2011" width="400" height="251" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>9992665263</strong></span></pre>
<p><strong>How to remove the infection of System Security 2011</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemSecurity2011" target="_blank">Adware.Win32.SystemSecurity2011</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Security 2012 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/19/av-protection-online-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Protection Online Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/23/av-protection-2011-rogue-removal-instructions/" rel="bookmark" class="crp_title">AV Protection 2011 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/cloud-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Cloud Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/25/cloud-av-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Cloud AV 2012 Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AV Protection Online Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/10/19/av-protection-online-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/10/19/av-protection-online-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 19 Oct 2011 16:54:07 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[AV Protection Online]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2686</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the AV Protection Online. Emsisoft Anti-Malware detects this malware as Adware.Win32.AVProtectionOnline. AV Protection Online is a rogue application. This is another variant of Guard Online and Cloud Protection. A rogue application tries to trick you by displaying false positive or misleading scan results report, [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>AV Protection Online</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.AVProtectionOnline" href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVProtectionOnline" target="_blank"><strong>Adware.Win32.AVProtectionOnline</strong></a><strong>.</strong></p>
<p><strong>AV Protection Online </strong><strong></strong>is                    a                                          rogue                            application.  This is another variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardOnline"><strong>Guard Online</strong></a> and <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.CloudProtection"><strong>Cloud Protection</strong></a>. A rogue application tries to trick  you   by    displaying false positive or  misleading scan results  report,   which  says   that your computer has a  problem, or infected  with   viruses or  trojan,   but you will not be able to  fix it before  you   purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%SystemRoot%\system32\[random].exe</li>
<li> %AppData%\[random]\</li>
<li> %AppData%\[random]\</li>
<li> %AppData%\[random]\</li>
<li> %AppData%\[random]\</li>
<li> %AppData%\[random]\AV Protection Online.ico</li>
<li> %AppData%\ldr.ini</li>
<li> %AppData%\svhostu.exe</li>
<li> %UserProfile%\Desktop\AV Protection Online.lnk</li>
<li> %UserProfile%\Local Settings\Temp\svhostu.exe</li>
<li> %UserProfile%\Local Settings\Temp\B.tmp</li>
<li> %UserProfile%\Start Menu\Programs\AV Protection Online\</li>
<li>%UserProfile%\Start Menu\Programs\AV Protection Online\AV Protection Online.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run\<br />
(String) [random] = %SystemRoot%\system32\[random].exe<br />
(String) [random] = %UserProfile%\Local Settings\Temp\svhostu.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.AVProtectionOnline_1.png"><img class="alignnone size-medium wp-image-2687" title="Adware.Win32.AVProtectionOnline" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.AVProtectionOnline_1-400x255.png" alt="Adware.Win32.AVProtectionOnline" width="400" height="255" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.AVProtectionOnline_2.png"><img class="alignnone size-medium wp-image-2688" title="Adware.Win32.AVProtectionOnline" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.AVProtectionOnline_2-400x334.png" alt="Adware.Win32.AVProtectionOnline" width="400" height="334" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.AVProtectionOnline_3.png"><img class="alignnone size-medium wp-image-2689" title="Adware.Win32.AVProtectionOnline" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.AVProtectionOnline_3-400x251.png" alt="Adware.Win32.AVProtectionOnline" width="400" height="251" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>9992665263</strong></span></pre>
<p><strong>How to remove the infection of AV Protection</strong><strong> Online </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVProtectionOnline" target="_blank">Adware.Win32.AVProtectionOnline</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">System Security 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Security 2012 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/guard-online-adware-removal-instructions/" rel="bookmark" class="crp_title">Guard Online Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/cloud-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Cloud Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/23/av-protection-2011-rogue-removal-instructions/" rel="bookmark" class="crp_title">AV Protection 2011 Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/10/19/av-protection-online-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cloud Protection Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/10/12/cloud-protection-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/10/12/cloud-protection-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 12 Oct 2011 15:29:01 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Cloud Protection]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2680</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Cloud Protection. Emsisoft Anti-Malware detects this malware as Adware.Win32.CloudProtection. Cloud Protection is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Cloud Protection</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.CloudProtection" href="http://www.emsisoft.com/en/malware/?Adware.Win32.CloudProtection" target="_blank"><strong>Adware.Win32.CloudProtection</strong></a><strong>.</strong></p>
<p><strong>Cloud Protection </strong><strong></strong><strong></strong>is                   a                                          rogue                           application.  A rogue application tries to trick you   by    displaying false positive or  misleading scan results report,   which  says   that your computer has a  problem, or infected with   viruses or  trojan,   but you will not be able to  fix it before you   purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\Internet Explorer\BE.tmp</li>
<li>%SystemRoot%\system32\%random%.exe</li>
<li>%AppData%\svhostu.exe</li>
<li>%AppData%\ldr.ini</li>
<li>%AppData%\%random%\</li>
<li>%AppData%\%random%\</li>
<li>%AppData%\%random%\</li>
<li>%AppData%\%random%\Cloud Protection.ico</li>
<li>%AppData%\%random%\</li>
<li>%UserProfile%\Desktop\Cloud Protection.lnk</li>
<li>%UserProfile%\Local Settings\Temp\BF.tmp</li>
<li>%UserProfile%\Local Settings\Temp\C1.tmp</li>
<li>%UserProfile%\Local Settings\Temp\svhostu.exe</li>
<li>%UserProfile%\Start Menu\Programs\Cloud Protection\</li>
<li>%UserProfile%\Start Menu\Programs\Cloud Protection\Cloud Protection.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Startup\crss.exe</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run<br />
&#8220;%random%=C:\WINDOWS\system32\%random%.exe&#8221;<br />
&#8220;%random%=%UserProfile%\Local Settings\Temp\svhostu.exe&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.CloudProtection_1.png"><img class="alignnone size-medium wp-image-2681" title="Adware.Win32.CloudProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.CloudProtection_1-400x255.png" alt="Adware.Win32.CloudProtection" width="400" height="255" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.CloudProtection_2.png"><img class="alignnone size-medium wp-image-2682" title="Adware.Win32.CloudProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.CloudProtection_2-400x334.png" alt="Adware.Win32.CloudProtection" width="400" height="334" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.CloudProtection_3.png"><img class="alignnone size-medium wp-image-2683" title="Adware.Win32.CloudProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.CloudProtection_3-400x251.png" alt="Adware.Win32.CloudProtection" width="400" height="251" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>9992665263</strong></span></pre>
<p><strong>How to remove the infection of Cloud Protection</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.CloudProtection" target="_blank">Adware.Win32.CloudProtection</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/10/19/av-protection-online-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Protection Online Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">System Security 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/25/cloud-av-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Cloud AV 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/23/av-protection-2011-rogue-removal-instructions/" rel="bookmark" class="crp_title">AV Protection 2011 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Security 2012 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/10/12/cloud-protection-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Guard Online Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/10/12/guard-online-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/10/12/guard-online-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 12 Oct 2011 09:07:51 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Guard Online]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2676</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Guard Online. Emsisoft Anti-Malware detects this malware as Adware.Win32.GuardOnline. Guard Online is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Guard Online</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.GuardOnline" href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardOnline" target="_blank"><strong>Adware.Win32.GuardOnline</strong></a><strong>.</strong></p>
<p><strong>Guard Online </strong><strong></strong><strong></strong>is                  a                                          rogue                          application.  A rogue application tries to trick you  by    displaying false positive or  misleading scan results report,  which  says   that your computer has a  problem, or infected with  viruses or  trojan,   but you will not be able to  fix it before you  purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\Internet Explorer\5C.tmp</li>
<li>%SystemRoot%\system32\%random%.exe</li>
<li>%AppData%\ldr.ini</li>
<li>%AppData%\%random%\</li>
<li>%AppData%\%random%\</li>
<li>%AppData%\%random%\Guard Online .ico</li>
<li>%AppData%\%random%\</li>
<li>%UserProfile%\Desktop\Guard Online .lnk</li>
<li>%UserProfile%\Local Settings\Temp\DX5B.tmp</li>
<li>%UserProfile%\Local Settings\Temp\DX5B.tmp.exe</li>
<li>%UserProfile%\Local Settings\Temp\5D.tmp</li>
<li>%UserProfile%\Start Menu\Programs\Guard Online\</li>
<li>%UserProfile%\Start Menu\Programs\Startup\crss.exe</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run<br />
&#8220;%random%=%SystemRoot%\system32\%random%.exe&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.GuardOnline_1.png"><img class="alignnone size-medium wp-image-2677" title="Adware.Win32.GuardOnline" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.GuardOnline_1-400x255.png" alt="Adware.Win32.GuardOnline" width="400" height="255" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.GuardOnline_2.png"><img class="alignnone size-medium wp-image-2678" title="Adware.Win32.GuardOnline" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.GuardOnline_2-400x334.png" alt="Adware.Win32.GuardOnline" width="400" height="334" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>9992665263</strong></span></pre>
<p><strong>How to remove the infection of Guard Online</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardOnline" target="_blank">Adware.Win32.GuardOnline</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/10/19/av-protection-online-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Protection Online Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">System Security 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Security 2012 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/06/av-guard-online-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Guard Online Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/23/av-protection-2011-rogue-removal-instructions/" rel="bookmark" class="crp_title">AV Protection 2011 Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/10/12/guard-online-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>System Restore Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/10/12/system-restore-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/10/12/system-restore-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 12 Oct 2011 08:54:26 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[System Restore]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2668</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the System Restore adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.SystemRestore. System Restore is a rogue application, another variant of Data Restore, Data Recovery, System Recovery, Master Utilities, PC Repair, HDD Repair and System Repair. A rogue application tries to trick you by displaying [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>System Restore </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.SystemRestore" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRestore" target="_blank"><strong>Adware.Win32.SystemRestore</strong></a><strong>.</strong></p>
<p><strong>System Restore </strong><strong></strong>is              a                                          rogue                      application, another variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataRestore"><strong>Data Restore</strong></a>, <strong><a title="Adware.Win32.DataRecovery" href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataRecovery" target="_blank">Data Recovery</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRecovery"><strong>System Recovery</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MasterUtilities"><strong>Master Utilities</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PCRepair"><strong>PC Repair</strong></a><strong>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDRepair"><strong>HDD Repair</strong></a> and <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRepair"><strong>System Repair</strong></a>.   A rogue application tries to trick you by displaying false positive or   misleading scan results report, which says that your computer has a   problem, or infected with viruses or trojan, but you will not be able to   fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfiles%\Application Data\~%random%r</li>
<li>%AllUsersProfiles%\Application Data\%random%.exe</li>
<li>%AllUsersProfiles%\Application Data\%random%.exe</li>
<li>%AllUsersProfiles%\Application Data\%random%</li>
<li>%AllUsersProfiles%\Application Data\~%random%</li>
<li>%UserProfile%\Desktop\System Restore.lnk</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\1\</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\2\</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\4\</li>
<li>%UserProfile%\Start Menu\Programs\System Restore\</li>
<li>%UserProfile%\Start Menu\Programs\System Restore\System Restore.lnk</li>
<li>%UserProfile%\Start Menu\Programs\System Restore\Uninstall System Restore.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\<br />
DisableTaskMgr: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\<br />
75fa38b7-8b94-4995-ad32-52e938867954:<br />
BD: 43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 74 00 73 00 20 00 61 00…</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\<br />
Use FormSuggest: “Yes”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\<br />
WarnonBadCertRecving: 0×00000000<br />
CertificateRevocation: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\<br />
NoChangingWallPaper: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\<br />
NoDesktop: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\<br />
LowRiskFileTypes:          “.zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;<br />
.mp3;.m3u;.wav;.scr;”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\<br />
SaveZoneInformation: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
%random%: “%AllUsersProfile%\Application Data\%random%.exe”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures: “no”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
Hidden: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
ShowSuperHidden: 0×00000000</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemRestore_1.png"><img class="alignnone size-medium wp-image-2670" title="Adware.Win32.SystemRestore" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemRestore_1-400x260.png" alt="Adware.Win32.SystemRestore" width="400" height="260" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemRestore_2.png"><img class="alignnone size-medium wp-image-2671" title="Adware.Win32.SystemRestore" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemRestore_2-400x260.png" alt="Adware.Win32.SystemRestore" width="400" height="260" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemRestore_3.png"><img class="alignnone size-medium wp-image-2672" title="Adware.Win32.SystemRestore" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemRestore_3-400x260.png" alt="Adware.Win32.SystemRestore" width="400" height="260" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemRestore_4.png"><img class="alignnone size-medium wp-image-2673" title="Adware.Win32.SystemRestore" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemRestore_4-400x229.png" alt="Adware.Win32.SystemRestore" width="400" height="229" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemRestore_5.png"><img class="alignnone size-medium wp-image-2674" title="Adware.Win32.SystemRestore" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemRestore_5-400x203.png" alt="Adware.Win32.SystemRestore" width="400" height="203" /></a></strong></p>
<p>To register and uninstall this rogue application, you can try the following serial number, and enter any email:</p>
<pre><span style="color: #ff0000;"><strong>1203978628012489708290478989147</strong>
<strong></strong></span></pre>
<p><strong>How to remove the infection of System Restore</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRestore" target="_blank">Adware.Win32.SystemRestore</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/10/03/data-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/15/system-fix-rogue-removal-instructions/" rel="bookmark" class="crp_title">System Fix Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/09/15/data-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/09/05/system-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">System Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/29/pc-repair-adware-removal-instructions/" rel="bookmark" class="crp_title">PC Repair Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/10/12/system-restore-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AV Guard Online Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/10/06/av-guard-online-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/10/06/av-guard-online-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 06 Oct 2011 06:09:56 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[AV Guard Online]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2659</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the AV Guard Online. Emsisoft Anti-Malware detects this malware as Adware.Win32.AVGuardOnline. AV Guard Online is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>AV Guard Online</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.AVGuardOnline" href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVGuardOnline" target="_blank"><strong>Adware.Win32.AVGuardOnline</strong></a><strong>.</strong></p>
<p><strong>AV Guard Online </strong><strong></strong><strong></strong>is                 a                                          rogue                         application.  A rogue application tries to trick you by    displaying false positive or  misleading scan results report, which  says   that your computer has a  problem, or infected with viruses or  trojan,   but you will not be able to  fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%SystemRoot%\system32\W1ivD3onFaHsJfL.exe</li>
<li>%SystemRoot%\system32\lvvm.exe</li>
<li>%AppData%\zA0uvS2ib3m5Q6EAV Guard Online.ico</li>
<li>%AppData%\conhost.exe</li>
<li>%AppData%\csrss.exe</li>
<li>%AppData%\E84E.1B6</li>
<li>%AppData%\ldr.ini</li>
<li>%AppData%\VwjUVelIBz0c\</li>
<li>%AppData%\zA0uvS2ib3m5Q6E\</li>
<li>%AppData%\nTZqjYCwkVzN\</li>
<li>%AppData%\Microsoft\csrss.exe</li>
<li>%UserProfile%\Desktop\AV Guard Online.lnk</li>
<li>%Temp%\4F.tmp</li>
<li>%Temp%\53.tmp</li>
<li>%Temp%\54.tmp</li>
<li>%Temp%\55.tmp</li>
<li>%UserProfile%\Start Menu\Programs\AV Guard Online\</li>
<li>%UserProfile%\Start Menu\Programs\AV Guard Online\AV Guard Online.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run<br />
&#8220;gTZqjYCkIrOyAuS8234A=%SystemRoot%\system32\W1ivD3onFaHsJfL.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run<br />
&#8220;conhost=%AppData%\Microsoft\csrss.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\system\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings<br />
&#8220;ProxyEnable=00000001&#8243;</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Internet Settings<br />
&#8220;ProxyEnable=00000001&#8243;</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Internet Settings<br />
&#8220;ProxyServer=http=127.0.0.1:53717&#8243;</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections<br />
&#8220;DefaultConnectionSettings=3C0000000B0000000&#8230;&#8221;</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections<br />
&#8220;SavedLegacySettings=3C0000006B0000000&#8230;&#8221;</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run<br />
&#8220;%RANDOM%=%AppData%\csrss.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Windows<br />
&#8220;Load=%SystemRoot%\system32\lvvm.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
&#8220;Shell=explorer.exe,%AppData%\conhost.exe&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.AVGuardOnline_1.png"><img class="alignnone size-medium wp-image-2660" title="Adware.Win32.AVGuardOnline" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.AVGuardOnline_1-400x301.png" alt="Adware.Win32.AVGuardOnline" width="400" height="301" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.AVGuardOnline_2.png"><img class="alignnone size-medium wp-image-2661" title="Adware.Win32.AVGuardOnline" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.AVGuardOnline_2-400x334.png" alt="Adware.Win32.AVGuardOnline" width="400" height="334" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.AVGuardOnline_3.png"><img class="alignnone size-medium wp-image-2662" title="Adware.Win32.AVGuardOnline" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.AVGuardOnline_3-400x251.png" alt="Adware.Win32.AVGuardOnline" width="400" height="251" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>9992665263</strong></span></pre>
<p><strong>How to remove the infection of AV Guard Online</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVGuardOnline" target="_blank">Adware.Win32.AVGuardOnline</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/10/12/guard-online-adware-removal-instructions/" rel="bookmark" class="crp_title">Guard Online Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/19/av-protection-online-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Protection Online Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">System Security 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/23/av-protection-2011-rogue-removal-instructions/" rel="bookmark" class="crp_title">AV Protection 2011 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/25/cloud-av-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Cloud AV 2012 Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/10/06/av-guard-online-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Guard 2012 Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/10/06/security-guard-2012-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/10/06/security-guard-2012-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 06 Oct 2011 05:50:54 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Security Guard 2012]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2653</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Security Guard 2012. Emsisoft Anti-Malware detects this malware as Adware.Win32.SecurityGuard2012. Security Guard 2012 is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Security Guard 2012</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.SecurityGuard2012" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecurityGuard2012" target="_blank"><strong>Adware.Win32.SecurityGuard2012</strong></a><strong>.</strong></p>
<p><strong>Security Guard 2012 </strong><strong></strong><strong></strong>is                a                                          rogue                        application.  A rogue application tries to trick you by   displaying false positive or  misleading scan results report, which says   that your computer has a  problem, or infected with viruses or trojan,   but you will not be able to  fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%SystemRoot%\system32\s4aQH6dWKfLhXjC.exe</li>
<li>%AppData%\livD2onF4Security Guard 2012.ico</li>
<li>%AppData%\GUVrlOBtx0c1b3n\</li>
<li>%AppData%\iXwjUCelItPyA\</li>
<li>%AppData%\livD2onF4\</li>
<li>%AppData%\ldr.ini</li>
<li>%UserProfile%\Desktop\Security Guard 2012.lnk</li>
<li>%Temp%\16.tmp</li>
<li>%UserProfile%\Start Menu\Programs\Security Guard 2012\</li>
<li>%UserProfile%\Start Menu\Programs\Security Guard 2012\Security Guard 2012.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run<br />
(String) OlIBrzPNyAuDoFp8234A = %SystemRoot%\system32\s4aQH6dWKfLhXjC.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SecurityGuard2012_1.png"><img class="alignnone size-medium wp-image-2654" title="Adware.Win32.SecurityGuard2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SecurityGuard2012_1-400x301.png" alt="Adware.Win32.SecurityGuard2012" width="400" height="301" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SecurityGuard2012_2.png"><img class="alignnone size-medium wp-image-2655" title="Adware.Win32.SecurityGuard2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SecurityGuard2012_2-400x334.png" alt="Adware.Win32.SecurityGuard2012" width="400" height="334" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SecurityGuard2012_3.png"><img class="alignnone size-medium wp-image-2656" title="Adware.Win32.SecurityGuard2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SecurityGuard2012_3-400x251.png" alt="Adware.Win32.SecurityGuard2012" width="400" height="251" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>9992665263</strong></span></pre>
<p><strong>How to remove the infection of Security Guard 2012</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecurityGuard2012" target="_blank">Adware.Win32.SecurityGuard2012</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Security 2012 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/25/cloud-av-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Cloud AV 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/23/internet-security-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/03/security-sphere-2012-removal-instructions/" rel="bookmark" class="crp_title">Security Sphere 2012 Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/guard-online-adware-removal-instructions/" rel="bookmark" class="crp_title">Guard Online Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/10/06/security-guard-2012-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Sphere 2012 Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/10/03/security-sphere-2012-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/10/03/security-sphere-2012-removal-instructions/#comments</comments>
		<pubDate>Mon, 03 Oct 2011 12:04:48 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Removal Instructions]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Security Sphere 2012]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2647</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Security Sphere 2012. Emsisoft Anti-Malware detects this malware as Trojan.Win32.SecuritySphere. Security Sphere 2012 is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Security Sphere 2012</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Trojan.Win32.SecuritySphere" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecuritySphere" target="_blank"><strong>Trojan.Win32.SecuritySphere</strong></a><strong>.</strong></p>
<p><strong>Security Sphere 2012 </strong><strong></strong><strong></strong>is               a                                          rogue                       application.  A rogue application tries to trick you by  displaying false positive or  misleading scan results report, which says  that your computer has a  problem, or infected with viruses or trojan,  but you will not be able to  fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfiles%\Application Data\%random%\</li>
<li>%AllUsersProfiles%\Application Data\%random%\%random%</li>
<li>%AllUsersProfiles%\Application Data\%random%\%random%.exe</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\%random%<br />
(String) &#8220;%AllUsersProfiles%\Application Data\%random%\%random%.exe&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/SecuritySphere2012.png"><img class="alignnone size-medium wp-image-2648" title="Security Sphere 2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/SecuritySphere2012-400x298.png" alt="Security Sphere 2012" width="400" height="298" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/SecuritySphere2012_2.png"><img class="alignnone size-medium wp-image-2649" title="Security Sphere 2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/SecuritySphere2012_2-366x400.png" alt="Security Sphere 2012" width="366" height="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/SecuritySphere2012_3.png"><img class="alignnone size-medium wp-image-2650" title="Security Sphere 2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/SecuritySphere2012_3-400x210.png" alt="Security Sphere 2012" width="400" height="210" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><strong><span style="color: #ff0000;">8945315-6548431</span></strong></pre>
<p><strong>How to remove the infection of Security Sphere 2012</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecuritySphere" target="_blank">Trojan.Win32.SecuritySphere</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/23/internet-security-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Security 2012 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/06/security-guard-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Guard 2012 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/23/smart-protection-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Smart Protection 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/19/xp-home-security-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">XP Home Security 2012 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/10/03/security-sphere-2012-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data Restore Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/10/03/data-restore-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/10/03/data-restore-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 03 Oct 2011 11:38:43 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Data Restore]]></category>
		<category><![CDATA[Defragmenter]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2641</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Data Restore adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.DataRestore. Data Restore is a rogue application, another variant of Data Recovery, System Recovery, Master Utilities, PC Repair, HDD Repair and System Repair. A rogue application tries to trick you by displaying false positive [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Data Restore </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.DataRestore" href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataRestore" target="_blank"><strong>Adware.Win32.DataRestore</strong></a><strong>.</strong></p>
<p><strong>Data Restore </strong><strong></strong>is              a                                          rogue                      application, another variant of <strong><a title="Adware.Win32.DataRecovery" href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataRecovery" target="_blank">Data Recovery</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRecovery"><strong>System Recovery</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MasterUtilities"><strong>Master Utilities</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PCRepair"><strong>PC Repair</strong></a><strong>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDRepair"><strong>HDD Repair</strong></a> and <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRepair"><strong>System Repair</strong></a>.  A rogue application tries to trick you by displaying false positive or  misleading scan results report, which says that your computer has a  problem, or infected with viruses or trojan, but you will not be able to  fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfiles%\Application Data\~%random%r</li>
<li>%AllUsersProfiles%\Application Data\%random%.exe</li>
<li>%AllUsersProfiles%\Application Data\%random%.exe</li>
<li>%AllUsersProfiles%\Application Data\%random%</li>
<li>%AllUsersProfiles%\Application Data\~%random%</li>
<li>%UserProfile%\Desktop\Data Restore.lnk</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\1\</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\2\</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\4\</li>
<li>%UserProfile%\Start Menu\Programs\Data Restore\</li>
<li>%UserProfile%\Start Menu\Programs\Data Restore\Data Restore.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Data Restore\Uninstall Data Restore.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\<br />
DisableTaskMgr: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\<br />
75fa38b7-8b94-4995-ad32-52e938867954:<br />
BD: 43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 74 00 73 00 20 00 61 00…</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\<br />
Use FormSuggest: “Yes”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\<br />
WarnonBadCertRecving: 0×00000000<br />
CertificateRevocation: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\<br />
NoChangingWallPaper: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\<br />
NoDesktop: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\<br />
LowRiskFileTypes:          “.zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;<br />
.mp3;.m3u;.wav;.scr;”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\<br />
SaveZoneInformation: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
%random%: “%AllUsersProfile%\Application Data\%random%.exe”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures: “no”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
Hidden: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
ShowSuperHidden: 0×00000000</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.DataRestore_1.png"><img class="alignnone size-medium wp-image-2642" title="Adware.Win32.DataRestore" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.DataRestore_1-400x260.png" alt="Adware.Win32.DataRestore" width="400" height="260" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.DataRestore_2.png"><img class="alignnone size-medium wp-image-2643" title="Adware.Win32.DataRestore" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.DataRestore_2-400x260.png" alt="Adware.Win32.DataRestore" width="400" height="260" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.DataRestore_3.png"><img class="alignnone size-medium wp-image-2644" title="Adware.Win32.DataRestore" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.DataRestore_3-400x260.png" alt="Adware.Win32.DataRestore" width="400" height="260" /></a></p>
<p>To register and uninstall this rogue application, you can try one of the following serial number, and enter any email:</p>
<pre><span style="color: #ff0000;"><strong>1203978628012489708290478989147</strong>
<strong>8475082234984902023718742058948</strong></span></pre>
<p><strong>How to remove the infection of Data Restore</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataRestore" target="_blank">Adware.Win32.DataRestore</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/10/12/system-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">System Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/15/system-fix-rogue-removal-instructions/" rel="bookmark" class="crp_title">System Fix Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/09/15/data-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/09/05/system-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">System Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/29/pc-repair-adware-removal-instructions/" rel="bookmark" class="crp_title">PC Repair Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/10/03/data-restore-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Total Protect Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/09/23/total-protect-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/09/23/total-protect-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 23 Sep 2011 16:50:44 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Adware.Win32.TotalProtectAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Total Protect]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2632</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Total Protect adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.TotalProtectAV. Total Protect is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Total Protect </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.TotalProtectAV" href="http://www.emsisoft.com/en/malware/?Adware.Win32.TotalProtectAV" target="_blank"><strong>Adware.Win32.TotalProtectAV</strong></a><strong>.</strong></p>
<p><strong>Total Protect </strong><strong></strong><strong></strong>is              a                                          rogue                      application.  A rogue application tries to trick you by displaying false positive or  misleading scan results report, which says that your computer has a  problem, or infected with viruses or trojan, but you will not be able to  fix it before you purchase.</p>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\RtlDriver32.exe</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run<br />
(String) {56321-2157-3235-3211} = %UserProfile%\Application Data\RtlDriver32.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.TotalProtectAV_1.png"><img class="alignnone size-medium wp-image-2633" title="Adware.Win32.TotalProtectAV" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.TotalProtectAV_1-400x224.png" alt="Adware.Win32.TotalProtectAV" width="400" height="224" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.TotalProtectAV_2.png"><img class="alignnone size-medium wp-image-2634" title="Adware.Win32.TotalProtectAV" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.TotalProtectAV_2-400x193.png" alt="Adware.Win32.TotalProtectAV" width="400" height="193" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.TotalProtectAV_4.png"><img class="alignnone size-medium wp-image-2635" title="Adware.Win32.TotalProtectAV" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.TotalProtectAV_4-400x225.png" alt="Adware.Win32.TotalProtectAV" width="400" height="225" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.TotalProtectAV_5.png"><img class="alignnone size-medium wp-image-2636" title="Adware.Win32.TotalProtectAV" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.TotalProtectAV_5-400x224.png" alt="Adware.Win32.TotalProtectAV" width="400" height="224" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.TotalProtectAV_6.png"><img class="alignnone size-medium wp-image-2637" title="Adware.Win32.TotalProtectAV" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.TotalProtectAV_6-400x220.png" alt="Adware.Win32.TotalProtectAV" width="400" height="220" /></a></p>
<p><strong>How to remove the infection of Total Protect</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TotalProtectAV" target="_blank">Adware.Win32.TotalProtectAV</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/08/19/security-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/06/11/personal-shield-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Personal Shield Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/07/24/security-shield-adware-removal-instructions-2/" rel="bookmark" class="crp_title">Security Shield Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/01/total-pc-defender-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">Total PC Defender 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/01/11/palladium-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Palladium Pro Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/09/23/total-protect-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data Recovery Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/09/15/data-recovery-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/09/15/data-recovery-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 15 Sep 2011 07:27:24 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Data Recovery]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2611</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Data Recovery adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.DataRecovery. Data Recovery is a rogue application, another variant of System Recovery, Master Utilities, PC Repair, HDD Repair and System Repair. A rogue application tries to trick you by displaying false positive or misleading [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Data Recovery </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.DataRecovery" href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataRecovery" target="_blank"><strong>Adware.Win32.DataRecovery</strong></a><strong>.</strong></p>
<p><strong>Data Recovery </strong><strong> </strong><strong></strong>is              a                                          rogue                      application, another variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRecovery"><strong>System Recovery</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MasterUtilities"><strong>Master Utilities</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PCRepair"><strong>PC Repair</strong></a><strong>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDRepair"><strong>HDD Repair</strong></a> and <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRepair"><strong>System Repair</strong></a>. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfiles%\Application Data\~%random%r</li>
<li>%AllUsersProfiles%\Application Data\%random%.exe</li>
<li>%AllUsersProfiles%\Application Data\%random%.exe</li>
<li>%AllUsersProfiles%\Application Data\%random%</li>
<li>%AllUsersProfiles%\Application Data\~%random%</li>
<li>%UserProfile%\Desktop\Data Recovery.lnk</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\1\</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\2\</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\4\</li>
<li>%UserProfile%\Start Menu\Programs\Data Recovery\</li>
<li>%UserProfile%\Start Menu\Programs\Data Recovery\Data Recovery.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Data Recovery\Uninstall Data Recovery.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\<br />
DisableTaskMgr: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\<br />
75fa38b7-8b94-4995-ad32-52e938867954:<br />
BD: 43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 74 00 73 00 20 00 61 00…</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\<br />
Use FormSuggest: “Yes”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\<br />
WarnonBadCertRecving: 0×00000000<br />
CertificateRevocation: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\<br />
NoChangingWallPaper: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\<br />
NoDesktop: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\<br />
LowRiskFileTypes:          “.zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;<br />
.mp3;.m3u;.wav;.scr;”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\<br />
SaveZoneInformation: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
%random%: “%AllUsersProfile%\Application Data\%random%.exe”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures: “no”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
Hidden: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
ShowSuperHidden: 0×00000000</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.DataRecovery_1.png"><img class="alignnone size-medium wp-image-2612" title="Adware.Win32.DataRecovery" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.DataRecovery_1-400x91.png" alt="Adware.Win32.DataRecovery" width="400" height="91" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.DataRecovery_3.png"><img class="alignnone size-medium wp-image-2613" title="Adware.Win32.DataRecovery" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.DataRecovery_3-400x260.png" alt="Adware.Win32.DataRecovery" width="400" height="260" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.DataRecovery_4.png"><img class="alignnone size-medium wp-image-2614" title="Adware.Win32.DataRecovery" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.DataRecovery_4-400x260.png" alt="Adware.Win32.DataRecovery" width="400" height="260" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.DataRecovery_5.png"><img class="alignnone size-medium wp-image-2615" title="Adware.Win32.DataRecovery" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.DataRecovery_5-400x260.png" alt="Adware.Win32.DataRecovery" width="400" height="260" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.DataRecovery_6.png"><img class="alignnone size-medium wp-image-2616" title="Adware.Win32.DataRecovery" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.DataRecovery_6-400x229.png" alt="Adware.Win32.DataRecovery" width="400" height="229" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.DataRecovery_7.png"><img class="alignnone size-medium wp-image-2617" title="Adware.Win32.DataRecovery" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.DataRecovery_7-400x245.png" alt="Adware.Win32.DataRecovery" width="400" height="245" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.DataRecovery_8.png"><img class="alignnone size-medium wp-image-2618" title="Adware.Win32.DataRecovery" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.DataRecovery_8-400x203.png" alt="Adware.Win32.DataRecovery" width="400" height="203" /></a></strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/serial-number.png"><img class="alignnone size-medium wp-image-2622" title="Data Recovery Rogue - Serial Number" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/serial-number-400x57.png" alt="Data Recovery Rogue - Serial Number" width="400" height="57" /></a></p>
<p>To register and uninstall this rogue application, you can try one of the following serial number, and enter any email:</p>
<pre><span style="color: #ff0000;"><strong>1203978628012489708290478989147</strong>
<strong>8475082234984902023718742058948</strong></span></pre>
<p><strong>How to remove the infection of Data Recovery</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataRecovery" target="_blank">Adware.Win32.DataRecovery</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/10/03/data-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/system-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">System Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/15/system-fix-rogue-removal-instructions/" rel="bookmark" class="crp_title">System Fix Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/09/05/system-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">System Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/29/pc-repair-adware-removal-instructions/" rel="bookmark" class="crp_title">PC Repair Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/09/15/data-recovery-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenCloud Security Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/09/05/opencloud-security-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/09/05/opencloud-security-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 05 Sep 2011 06:38:35 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[OpenCloud Security]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2603</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the OpenCloud Security adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.OpenCloudSecurity. OpenCloud Security is a rogue application, another variant of OpenCloud Antivirus. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>OpenCloud Security </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.OpenCloudSecurity" href="http://www.emsisoft.com/en/malware/?Adware.Win32.OpenCloudSecurity" target="_blank"><strong>Adware.Win32.OpenCloudSecurity</strong></a><strong>.</strong></p>
<p><strong>OpenCloud Security </strong><strong></strong><strong></strong>is              a                                          rogue                      application, another variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.OpenCloudAntivirus"><strong>OpenCloud Antivirus</strong></a>.     A           rogue                              application                   tries       to         trick  you   by                                                             displaying                                       false                                                         positive  or  misleading                  scan                                             results                                  report,         which           says                           that    your                                                                        computer               has    a                problem,                or             infected             with                                               viruses                or                       trojan,            but            you             will                           not                  be           able                       to     fix         it                       before            you                                        purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%UserProfile%\Application Data\OpenCloud Security\</li>
<li> %UserProfile%\Application Data\OpenCloud Security\OpenCloud Security.ico</li>
<li> %UserProfile%\Application Data\OpenCloud Security\wf.conf</li>
<li> %UserProfile%\Application Data\OpenCloud Security\OpenCloud Security.exe</li>
<li> %UserProfile%\Desktop\OpenCloud Security.lnk</li>
<li> %UserProfile%\Local Settings\Temp\1.tmp</li>
<li> %UserProfile%\Start Menu\Programs\OpenCloud Security\</li>
<li>%UserProfile%\Start Menu\Programs\OpenCloud Security\OpenCloud Security.lnk</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.OpenCloudSecurity_1.png"><img class="alignnone size-medium wp-image-2604" title="Adware.Win32.OpenCloudSecurity" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.OpenCloudSecurity_1-400x301.png" alt="Adware.Win32.OpenCloudSecurity" width="400" height="301" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.OpenCloudSecurity_2.png"><img class="alignnone size-medium wp-image-2605" title="Adware.Win32.OpenCloudSecurity" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.OpenCloudSecurity_2-400x301.png" alt="Adware.Win32.OpenCloudSecurity" width="400" height="301" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.OpenCloudSecurity_3.png"><img class="alignnone size-medium wp-image-2606" title="Adware.Win32.OpenCloudSecurity" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.OpenCloudSecurity_3-400x334.png" alt="Adware.Win32.OpenCloudSecurity" width="400" height="334" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.OpenCloudSecurity_4.png"><img class="alignnone size-medium wp-image-2607" title="Adware.Win32.OpenCloudSecurity" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.OpenCloudSecurity_4-400x251.png" alt="Adware.Win32.OpenCloudSecurity" width="400" height="251" /></a></p>
<p><strong>How to remove the infection of OpenCloud Security </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.OpenCloudSecurity">Adware.Win32.OpenCloudSecurity</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                         Anti-Malware</a></strong>. Run a full scan on all  drives      and      move     all detected          items to the  quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/08/29/opencloud-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">OpenCloud Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/11/pc-security-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">PC Security 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/13/wolfram-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">Wolfram Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/07/24/security-shield-adware-removal-instructions-2/" rel="bookmark" class="crp_title">Security Shield Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/19/security-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Protection Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/09/05/opencloud-security-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>System Recovery Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/09/05/system-recovery-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/09/05/system-recovery-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 05 Sep 2011 06:28:03 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[System Recovery]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2596</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the System Recovery adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.SystemRecovery. System Recovery is a rogue application, another variant of Master Utilities, PC Repair, HDD Repair and System Repair. A rogue application tries to trick you by displaying false positive or misleading scan results [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>System Recovery </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.SystemRecovery" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRecovery" target="_blank"><strong>Adware.Win32.SystemRecovery</strong></a><strong>.</strong></p>
<p><strong>System Recovery </strong><strong></strong><strong></strong>is              a                                          rogue                      application, another variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MasterUtilities"><strong>Master Utilities</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PCRepair"><strong>PC Repair</strong></a><strong>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDRepair"><strong>HDD Repair</strong></a> and <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRepair"><strong>System Repair</strong></a>.    A           rogue                              application                  tries       to         trick  you   by                                                            displaying                                      false                                                        positive  or  misleading                  scan                                            results                                  report,        which           says                           that    your                                                                       computer              has    a                problem,                or            infected             with                                              viruses                or                       trojan,            but           you             will                           not                 be           able                       to     fix         it                      before            you                                       purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfiles%\Application Data\~%random%r</li>
<li>%AllUsersProfiles%\Application Data\%random%.exe</li>
<li>%AllUsersProfiles%\Application Data\%random%</li>
<li>%AllUsersProfiles%\Application Data\~%random%</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\System Recovery.lnk</li>
<li>%UserProfile%\Desktop\System Recovery.lnk</li>
<li>%UserProfile%\Local Settings\Temp\tmp1914.tmp</li>
<li>%UserProfile%\Start Menu\Programs\System Recovery\</li>
<li>%UserProfile%\Start Menu\Programs\System Recovery\System Recovery.lnk</li>
<li>%UserProfile%\Start Menu\Programs\System Recovery\Uninstall System Recovery.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\<br />
DisableTaskMgr: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\<br />
75fa38b7-8b94-4995-ad32-52e938867954:<br />
BD: 43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 74 00 73 00 20 00 61 00…</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\<br />
Use FormSuggest: “Yes”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\<br />
WarnonBadCertRecving: 0×00000000<br />
CertificateRevocation: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\<br />
NoChangingWallPaper: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\<br />
LowRiskFileTypes:         “/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\<br />
SaveZoneInformation: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
%random%: “%AllUsersProfile%\Application Data\%random%.exe”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures: “no”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
Hidden: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
ShowSuperHidden: 0×00000000</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.SystemRecovery_1.png"><img class="alignnone size-medium wp-image-2597" title="Adware.Win32.SystemRecovery" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.SystemRecovery_1-400x260.png" alt="Adware.Win32.SystemRecovery" width="400" height="260" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.SystemRecovery_2.png"><img class="alignnone size-medium wp-image-2598" title="Adware.Win32.SystemRecovery" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.SystemRecovery_2-400x260.png" alt="Adware.Win32.SystemRecovery" width="400" height="260" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.SystemRecovery_3.png"><img class="alignnone size-medium wp-image-2599" title="Adware.Win32.SystemRecovery" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.SystemRecovery_3-400x260.png" alt="Adware.Win32.SystemRecovery" width="400" height="260" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.SystemRecovery_4.png"><img class="alignnone size-medium wp-image-2600" title="Adware.Win32.SystemRecovery" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.SystemRecovery_4-400x260.png" alt="Adware.Win32.SystemRecovery" width="400" height="260" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.SystemRecovery_5.png"><img class="alignnone size-medium wp-image-2601" title="Adware.Win32.SystemRecovery" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.SystemRecovery_5-400x192.png" alt="Adware.Win32.SystemRecovery" width="400" height="192" /></a></strong></p>
<p>To register and uninstall this rogue application, you can try one of the following serial number, and enter any email:</p>
<pre><span style="color: #ff0000;"><strong>1203978628012489708290478989147</strong>
<strong>8475082234984902023718742058948</strong></span></pre>
<p><strong>How to remove the infection of System Recovery</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRecovery" target="_blank">Adware.Win32.SystemRecovery</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/09/15/data-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/system-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">System Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/03/data-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/15/system-fix-rogue-removal-instructions/" rel="bookmark" class="crp_title">System Fix Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/09/05/master-utilities-adware-removal-instructions/" rel="bookmark" class="crp_title">Master Utilities Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/09/05/system-recovery-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Master Utilities Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/09/05/master-utilities-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/09/05/master-utilities-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 05 Sep 2011 06:21:37 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Master Utilities]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2590</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Master Utilities adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.MasterUtilities. Master Utilities is a rogue application, another variant of PC Repair, HDD Repair and System Repair. A rogue application tries to trick you by displaying false positive or misleading scan results report, which [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Master Utilities </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.MasterUtilities" href="http://www.emsisoft.com/en/malware/?Adware.Win32.MasterUtilities" target="_blank"><strong>Adware.Win32.MasterUtilities</strong></a><strong>.</strong></p>
<p><strong>Master Utilities </strong><strong></strong><strong></strong>is              a                                          rogue                      application, another variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PCRepair"><strong>PC Repair</strong></a><strong>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDRepair"><strong>HDD Repair</strong></a> and <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRepair"><strong>System Repair</strong></a>.   A           rogue                              application                 tries       to         trick  you   by                                                           displaying                                     false                                                       positive  or  misleading                  scan                                           results                                  report,       which           says                           that    your                                                                      computer             has    a                problem,                or           infected             with                                             viruses                or                       trojan,            but          you             will                           not                be           able                       to     fix         it                     before            you                                      purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfiles%\Application Data\~%random%r</li>
<li>%AllUsersProfiles%\Application Data\%random%.exe</li>
<li>%AllUsersProfiles%\Application Data\%random%</li>
<li>%AllUsersProfiles%\Application Data\~%random%</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Master Utilities.lnk</li>
<li>%UserProfile%\Desktop\Master Utilities.lnk</li>
<li>%UserProfile%\Local Settings\Temp\tmp7CC8.tmp</li>
<li>%UserProfile%\Start Menu\Programs\Master Utilities\</li>
<li>%UserProfile%\Start Menu\Programs\Master Utilities\Master Utilities.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Master Utilities\Uninstall Master Utilities.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\<br />
DisableTaskMgr: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\<br />
75fa38b7-8b94-4995-ad32-52e938867954:<br />
BD: 43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 74 00 73 00 20 00 61 00…</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\<br />
Use FormSuggest: “Yes”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\<br />
WarnonBadCertRecving: 0×00000000<br />
CertificateRevocation: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\<br />
NoChangingWallPaper: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\<br />
LowRiskFileTypes:        “/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\<br />
SaveZoneInformation: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
%random%: “%AllUsersProfile%\Application Data\%random%.exe”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures: “no”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
Hidden: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
ShowSuperHidden: 0×00000000</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.MasterUtilities_1.png"><img class="alignnone size-medium wp-image-2591" title="Adware.Win32.MasterUtilities" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.MasterUtilities_1-400x260.png" alt="Adware.Win32.MasterUtilities" width="400" height="260" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.MasterUtilities_2.png"><img class="alignnone size-medium wp-image-2592" title="Adware.Win32.MasterUtilities" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.MasterUtilities_2-400x260.png" alt="Adware.Win32.MasterUtilities" width="400" height="260" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.MasterUtilities_3.png"><img class="alignnone size-medium wp-image-2593" title="Adware.Win32.MasterUtilities" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.MasterUtilities_3-400x260.png" alt="Adware.Win32.MasterUtilities" width="400" height="260" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.MasterUtilities_4.png"><img class="alignnone size-medium wp-image-2594" title="Adware.Win32.MasterUtilities" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/09/Adware.Win32.MasterUtilities_4-400x192.png" alt="Adware.Win32.MasterUtilities" width="400" height="192" /></a></strong></p>
<p>To register and uninstall this rogue application, you can try one of the following serial number, and enter any email:</p>
<pre><span style="color: #ff0000;"><strong>1203978628012489708290478989147</strong>
<strong>8475082234984902023718742058948</strong></span></pre>
<p><strong>How to remove the infection of Master Utilities</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MasterUtilities" target="_blank">Adware.Win32.MasterUtilities</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/09/05/system-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">System Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/03/data-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/15/system-fix-rogue-removal-instructions/" rel="bookmark" class="crp_title">System Fix Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/system-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">System Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/09/15/data-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Recovery Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/09/05/master-utilities-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PC Repair Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/08/29/pc-repair-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/08/29/pc-repair-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 29 Aug 2011 20:11:15 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[PC Repair]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2583</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the PC Repair adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.PCRepair. PC Repair is a rogue application, another variant of HDD Repair and System Repair. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>PC Repair </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.PCRepair" href="http://www.emsisoft.com/en/malware/?Adware.Win32.PCRepair" target="_blank"><strong>Adware.Win32.PCRepair</strong></a><strong>.</strong></p>
<p><strong>PC Repair</strong><strong> </strong><strong></strong>is              a                                          rogue                      application, another variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDRepair"><strong>HDD Repair</strong></a> and <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRepair"><strong>System Repair</strong></a>.  A           rogue                              application                tries       to         trick  you   by                                                          displaying                                    false                                                       positive or  misleading                  scan                                          results                                  report,       which          says                           that    your                                                                     computer             has    a               problem,                or           infected            with                                             viruses               or                       trojan,            but          you            will                           not                be           able                      to     fix         it                     before           you                                      purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfiles%\Application Data\~%random%r</li>
<li>%AllUsersProfiles%\Application Data\%random%.exe</li>
<li>%AllUsersProfiles%\Application Data\%random%</li>
<li>%AllUsersProfiles%\Application Data\~%random%</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PC Repair.lnk</li>
<li>%UserProfile%\Desktop\PC Repair.lnk</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\4\</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\1\</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\2\</li>
<li>%UserProfile%\Start Menu\Programs\PC Repair\</li>
<li>%UserProfile%\Start Menu\Programs\PC Repair\PC Repair.lnk</li>
<li>%UserProfile%\Start Menu\Programs\PC Repair\Uninstall PC Repair.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\<br />
DisableTaskMgr: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\<br />
75fa38b7-8b94-4995-ad32-52e938867954:<br />
BD: 43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 74 00 73 00 20 00 61 00…</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\<br />
Use FormSuggest: “Yes”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\<br />
WarnonBadCertRecving: 0×00000000<br />
CertificateRevocation: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\<br />
NoChangingWallPaper: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\<br />
LowRiskFileTypes:       “/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\<br />
SaveZoneInformation: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
%random%: “%AllUsersProfile%\Application Data\%random%.exe”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures: “no”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
Hidden: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
ShowSuperHidden: 0×00000000</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.PCRepair_1.png"><img class="alignnone size-medium wp-image-2584" title="Adware.Win32.PCRepair" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.PCRepair_1-400x240.png" alt="Adware.Win32.PCRepair" width="400" height="240" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.PCRepair_2.png"><img class="alignnone size-medium wp-image-2585" title="Adware.Win32.PCRepair" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.PCRepair_2-400x240.png" alt="Adware.Win32.PCRepair" width="400" height="240" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.PCRepair_3.png"><img class="alignnone size-medium wp-image-2586" title="Adware.Win32.PCRepair" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.PCRepair_3-400x240.png" alt="Adware.Win32.PCRepair" width="400" height="240" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.PCRepair_4.png"><img class="alignnone size-medium wp-image-2587" title="Adware.Win32.PCRepair" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.PCRepair_4-400x240.png" alt="Adware.Win32.PCRepair" width="400" height="240" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.PCRepair_5.png"><img class="alignnone size-medium wp-image-2588" title="Adware.Win32.PCRepair" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.PCRepair_5-400x192.png" alt="Adware.Win32.PCRepair" width="400" height="192" /></a></strong></p>
<p>To register and uninstall this rogue application, you can try one of the following serial number, and enter any email:</p>
<pre><span style="color: #ff0000;"><strong>1203978628012489708290478989147</strong>
<strong>8475082234984902023718742058948</strong></span></pre>
<p><strong>How to remove the infection of PC </strong><strong>Repair </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PCRepair" target="_blank">Adware.Win32.PCRepair</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/08/26/hdd-repair-adware-removal-instructions/" rel="bookmark" class="crp_title">HDD Repair Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/19/system-repair-adware-removal-instructions/" rel="bookmark" class="crp_title">System Repair Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/03/data-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/system-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">System Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/09/15/data-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Recovery Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/08/29/pc-repair-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenCloud Antivirus Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/08/29/opencloud-antivirus-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/08/29/opencloud-antivirus-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 29 Aug 2011 20:04:00 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[OpenCloud Antivirus]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2578</guid>
		<description><![CDATA[The Emsisoft malware research team has discoverd a new outbreak of the OpenCloud Antivirus adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.OpenCloudAntivirus. OpenCloud Antivirus is a rogue security program, this is a new variant of Wireshark Antivirus, SysAntivirus (alias Sysinternals Antivirus), XJR Antivirus, AKM Antivirus 2010 Pro and RTS Antivirus 2010. The maker of this [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.emsisoft.com/" target="_blank"><strong>Emsisoft</strong></a> malware research team has           discoverd a new outbreak               of the<strong> OpenCloud Antivirus </strong> adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                         Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.OpenCloudAntivirus" target="_blank"><strong>Adware.Win32.OpenCloudAntivirus</strong></a>.</p>
<p><strong>OpenCloud Antivirus </strong>is a rogue security program, this is a  new variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WiresharkAntivirus"><strong>Wireshark Antivirus</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SysAntivirus" target="_blank"><strong>SysAntivirus</strong></a> (alias Sysinternals Antivirus), <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.XJRAntivirus" target="_blank"><strong>XJR Antivirus</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AKMAntivirus2010Pro" target="_blank"><strong>AKM Antivirus 2010 Pro</strong></a> and <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.RTSAntivirus2010" target="_blank">RTS Antivirus 2010</a></strong>. The maker of this rogue give it name as <strong>Sysinternals Antivirus</strong>.   A  rogue      application         tries to  trick you  by displaying     false         positive/misleading   scan        results  report, which     says that  your         computer is  infected   with       viruses  or    trojan, but  you     will not be     able   to  delete  them   before  you        purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%UserProfile%\Application Data\OpenCloud Antivirus\</li>
<li> %UserProfile%\Application Data\OpenCloud Antivirus\OpenCloud Antivirus.ico</li>
<li> %UserProfile%\Application Data\OpenCloud Antivirus\wf.conf</li>
<li> %UserProfile%\Application Data\OpenCloud Antivirus\OpenCloud Antivirus.exe</li>
<li> %UserProfile%\Desktop\OpenCloud Antivirus.lnk</li>
<li> %UserProfile%\Local Settings\Temp\1.tmp</li>
<li> %UserProfile%\Start Menu\Programs\OpenCloud Antivirus\</li>
<li>%UserProfile%\Start Menu\Programs\OpenCloud Antivirus\OpenCloud Antivirus.lnk</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.OpenCloudAntivirus_1.png"><img class="alignnone size-medium wp-image-2579" title="Adware.Win32.OpenCloudAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.OpenCloudAntivirus_1-400x301.png" alt="Adware.Win32.OpenCloudAntivirus" width="400" height="301" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.OpenCloudAntivirus_2.png"><img class="alignnone size-medium wp-image-2580" title="Adware.Win32.OpenCloudAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.OpenCloudAntivirus_2-400x334.png" alt="Adware.Win32.OpenCloudAntivirus" width="400" height="334" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.OpenCloudAntivirus_3.png"><img class="alignnone size-medium wp-image-2581" title="Adware.Win32.OpenCloudAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.OpenCloudAntivirus_3-400x251.png" alt="Adware.Win32.OpenCloudAntivirus" width="400" height="251" /></a></p>
<p><strong>How to remove the infection of OpenCloud Antivirus </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.OpenCloudAntivirus">Adware.Win32.OpenCloudAntivirus</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                         Anti-Malware</a></strong>. Run a full scan on all  drives      and      move     all detected          items to the  quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/09/05/opencloud-security-adware-removal-instructions/" rel="bookmark" class="crp_title">OpenCloud Security Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/06/sysantivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">SysAntivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/05/blueflare-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">BlueFlare Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/13/wolfram-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">Wolfram Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/08/11/wireshark-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">Wireshark Antivirus Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/08/29/opencloud-antivirus-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HDD Repair Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/08/26/hdd-repair-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/08/26/hdd-repair-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 26 Aug 2011 21:40:48 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Defragmenter]]></category>
		<category><![CDATA[HDD Repair]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2565</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the HDD Repair adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.HDDRepair. HDD Repair is a rogue application, another variant of System Repair. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>HDD Repair </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.HDDRepair" href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDRepair" target="_blank"><strong>Adware.Win32.HDDRepair</strong></a><strong>.</strong></p>
<p><strong>HDD Repair</strong><strong> </strong><strong></strong>is              a                                          rogue                      application, another variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRepair"><strong>System Repair</strong></a>. A           rogue                              application               tries       to         trick  you   by                                                         displaying                                   false                                                       positive or misleading                  scan                                         results                                  report,       which         says                           that    your                                                                    computer             has    a              problem,                or           infected            with                                            viruses               or                      trojan,            but          you            will                          not                be           able                     to     fix         it                     before           you                                     purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfiles%\Application Data\~%random%r</li>
<li>%AllUsersProfiles%\Application Data\%random%.exe</li>
<li>%AllUsersProfiles%\Application Data\%random%</li>
<li>%AllUsersProfiles%\Application Data\~%random%</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\HDD Repair.lnk</li>
<li>%UserProfile%\Desktop\HDD Repair.lnk</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\4\</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\1\</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\2\</li>
<li>%UserProfile%\Start Menu\Programs\HDD Repair\</li>
<li>%UserProfile%\Start Menu\Programs\HDD Repair\HDD Repair.lnk</li>
<li>%UserProfile%\Start Menu\Programs\HDD Repair\Uninstall HDD Repair.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\<br />
DisableTaskMgr: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\<br />
75fa38b7-8b94-4995-ad32-52e938867954:<br />
BD: 43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 74 00 73 00 20 00 61 00…</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\<br />
Use FormSuggest: “Yes”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\<br />
WarnonBadCertRecving: 0×00000000<br />
CertificateRevocation: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\<br />
NoChangingWallPaper: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\<br />
LowRiskFileTypes:      “/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\<br />
SaveZoneInformation: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
%random%: “%AllUsersProfile%\Application Data\%random%.exe”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures: “no”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
Hidden: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
ShowSuperHidden: 0×00000000</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.HDDRepair_1.png"><img class="alignnone size-medium wp-image-2566" title="Adware.Win32.HDDRepair" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.HDDRepair_1-400x240.png" alt="Adware.Win32.HDDRepair" width="400" height="240" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.HDDRepair_2.png"><img class="alignnone size-medium wp-image-2567" title="Adware.Win32.HDDRepair" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.HDDRepair_2-400x240.png" alt="Adware.Win32.HDDRepair" width="400" height="240" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.HDDRepair_3.png"><img class="alignnone size-medium wp-image-2568" title="Adware.Win32.HDDRepair" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.HDDRepair_3-400x240.png" alt="Adware.Win32.HDDRepair" width="400" height="240" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.HDDRepair_4.png"><img class="alignnone size-medium wp-image-2569" title="Adware.Win32.HDDRepair" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.HDDRepair_4-400x240.png" alt="Adware.Win32.HDDRepair" width="400" height="240" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.HDDRepair_5.png"><img class="alignnone size-medium wp-image-2570" title="Adware.Win32.HDDRepair" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.HDDRepair_5-400x228.png" alt="Adware.Win32.HDDRepair" width="400" height="228" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.HDDRepair_6.png"><img class="alignnone size-medium wp-image-2571" title="Adware.Win32.HDDRepair" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.HDDRepair_6-400x267.png" alt="Adware.Win32.HDDRepair" width="400" height="267" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.HDDRepair_7.png"><img class="alignnone size-medium wp-image-2572" title="Adware.Win32.HDDRepair" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.HDDRepair_7-400x192.png" alt="Adware.Win32.HDDRepair" width="400" height="192" /></a></p>
<p>To register and uninstall this rogue application, you can try one of the following serial number, and enter any email:</p>
<pre><span style="color: #ff0000;"><strong>1203978628012489708290478989147</strong>
<strong>8475082234984902023718742058948</strong></span></pre>
<p><strong>How to remove the infection of </strong><strong>HDD Repair </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDRepair" target="_blank">Adware.Win32.HDDRepair</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/08/29/pc-repair-adware-removal-instructions/" rel="bookmark" class="crp_title">PC Repair Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/19/system-repair-adware-removal-instructions/" rel="bookmark" class="crp_title">System Repair Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/03/data-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/09/15/data-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/system-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">System Restore Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/08/26/hdd-repair-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Home Safety Essentials Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/08/19/home-safety-essentials-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/08/19/home-safety-essentials-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 19 Aug 2011 21:46:16 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Home Safety Essentials]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2557</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Home Safety Essentials adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.HomeSafetyEssentials. Home Safety Essentials is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Home Safety Essentials </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.HomeSafetyEssentials" href="http://www.emsisoft.com/en/malware/?Adware.Win32.HomeSafetyEssentials" target="_blank"><strong>Adware.Win32.HomeSafetyEssentials</strong></a><strong>.</strong></p>
<p><strong>Home Safety Essentials</strong><strong> </strong><strong></strong>is              a                                          rogue                      application. A           rogue                              application               tries       to         trick  you   by                                                         displaying                                   false                                                       positive or misleading                  scan                                         results                                  report,       which         says                           that    your                                                                    computer             has    a              problem,                or           infected            with                                            viruses               or                      trojan,            but          you            will                          not                be           able                     to     fix         it                     before           you                                     purchase. Home Safety Essentials will also   create  numerous harmless files on the infected computer,    usually at Recent   folder.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\%random%\</li>
<li>%AllUsersProfile%\Application Data\%random%\Quarantine Items\</li>
<li>%AllUsersProfile%\Application Data\%random%\BackUp\</li>
<li>%AllUsersProfile%\Application Data\%random%\HSESys\</li>
<li>%AllUsersProfile%\Application Data\%random%\32.mof</li>
<li>%AllUsersProfile%\Application Data\%random%\HS73f_231.exe</li>
<li>%AllUsersProfile%\Application Data\%random%\HSE.ico</li>
<li>%AllUsersProfile%\Application Data\%random%\mozcrt19.dll</li>
<li>%AllUsersProfile%\Application Data\%random%\sqlite3.dll</li>
<li>%AllUsersProfile%\Application Data\HSKLURAFE\</li>
<li>%AllUsersProfile%\Application Data\HSKLURAFE\HSGRZHE.cfg</li>
<li>%UserProfile%\Application Data\Home Safety Essentials\</li>
<li>%UserProfile%\Application Data\Home Safety Essentials\cookies.sqlite</li>
<li>%UserProfile%\Application Data\Home Safety Essentials\Instructions.ini</li>
<li>%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Home Safety Essentials.lnk</li>
<li>%UserProfile%\Desktop\Home Safety Essentials.lnk</li>
<li>%UserProfile%\Recent\SICKBOY.exe</li>
<li>%UserProfile%\Recent\sld.sys</li>
<li>%UserProfile%\Recent\SM.exe</li>
<li>%UserProfile%\Recent\std.sys</li>
<li>%UserProfile%\Recent\tjd.dll</li>
<li>%UserProfile%\Recent\tjd.exe</li>
<li>%UserProfile%\Recent\cb.tmp</li>
<li>%UserProfile%\Recent\CLSV.dll</li>
<li>%UserProfile%\Recent\delfile.sys</li>
<li>%UserProfile%\Recent\eb.tmp</li>
<li>%UserProfile%\Recent\energy.tmp</li>
<li>%UserProfile%\Recent\exec.drv</li>
<li>%UserProfile%\Recent\fix.drv</li>
<li>%UserProfile%\Recent\fix.sys</li>
<li>%UserProfile%\Recent\PE.exe</li>
<li>%UserProfile%\Recent\PE.sys</li>
<li>%UserProfile%\Recent\ppal.dll</li>
<li>%UserProfile%\Start Menu\Home Safety Essentials.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Home Safety Essentials.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ProgID\: &#8220;HS73f_231.DocHostUIHandler&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\LocalServer32\: &#8220;%AllUsersProfile%\APPLIC~1\73f1ad\HS73F_~1.EXE&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\: &#8220;Implements DocHostUIHandler&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Classes\HS73f_231.DocHostUIHandler\Clsid\: &#8220;{3F2BBC05-40DF-11D2-9455-00104BC936FF}&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Classes\HS73f_231.DocHostUIHandler\: &#8220;Implements DocHostUIHandler&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\install.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AluSchedulerSvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\amon9x.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\anti-trojan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirus.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ants.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\apimonitor.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aplica32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\apvxdwin.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\arr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Arrakis3.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashAvast.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashBug.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashChest.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashCnsnt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashLogV.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashMaiSv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashPopWz.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashQuick.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashServ.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSimp2.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSimpl.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSkPcc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSkPck.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashUpd.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashWebSv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswChLic.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswRegSvr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswRunDll.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswUpdSv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\atcon.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\atguard.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\atro55en.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\atupdater.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\atwatch.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\au.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aupdate.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\auto-protect.nav80try.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\autodown.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\autotrace.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoupdate.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avadmin.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avcenter.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avciman.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconfig.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconsol.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ave32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcc32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgchk.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcmgr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcsrvx.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgctrl.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgdumpx.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgemc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgiproxy.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnsx.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrsx.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgscanx.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgserv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgserv9.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgsrmax.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgtray.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgui.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgupd.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgwdsvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkpop.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkserv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkservice.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkwctl9.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avltmain.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avmailc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avmcdlg.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avnotify.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avnt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpcc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpdos32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpm.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avptc32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpupd.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avsched32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avsynmgr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avupgsvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVWEBGRD.EXE\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwin.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwin95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwinnt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwsc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupd.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupd32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupsrv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxmonitor9x.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxmonitornt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxquar.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\b.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\backweb.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bargains.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdagent.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvcl.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvwiz.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDInProcPatch.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdmcon.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDMsnScan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdreinit.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdsubwiz.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDSurvey.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdtkexec.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdwizreg.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bd_professional.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\beagle.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\belt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bidef.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bidserver.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bipcp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bipcpevalsetup.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bisp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\blackd.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\blackice.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\blink.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\blss.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bootconf.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bootwarn.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\borg2.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\brasil.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\brw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bs120.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bspatch.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bundle.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bvt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\c.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cavscan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccapp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccevtmgr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccpxysvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccSvcHst.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cdp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfd.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfgwiz.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfiadmin.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfiaudit.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfinet.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfinet32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfpconfg.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfplogvw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfpupdat.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cl.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\claw95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\claw95cf.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\clean.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleaner.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleaner3.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleanIELow.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleanpc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\click.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmdagent.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmesys.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmgrdian.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmon016.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\connectionmonitor.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\control\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpd.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpf9x206.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpfnt206.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\crashrep.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssconfg.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssupdat.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssurf.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctrl.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cwnb181.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cwntdwmo.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\d.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\datemanager.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dcomx.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\defalert.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\defscangui.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\defwatch.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deloeminfs.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deputy.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dllcache.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dllreg.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\doors.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpf.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpfsetup.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpps2.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\driverctrl.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\drwatson.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\drweb32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\drwebupw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dssagent.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dvp95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dvp95_0.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ecengine.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\efpeadm.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\emsw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ent.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\esafe.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\escanhnt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\escanv95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\espwatch.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ethereal.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\etrustcipe.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\evpn.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\exantivirus-cnet.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\exe.avxw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\expert.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explore.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-agnt95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-prot.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-prot95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-stopw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fact.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fameh32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fast.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fch32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fih32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\findviru.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\firewall.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fixcfg.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fixfp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fnrb32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fp-win.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fp-win_trial.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fprot.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\frmwrk32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\frw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsaa.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav530stbyb.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav530wtbyb.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsgk32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsm32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsma32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsmb32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gator.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gav.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbmenu.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbpoll.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\generics.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gmt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\guard.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\guarddog.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\guardgui.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hacktracersetup.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hbinst.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hbsrv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\History.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\homeav2010.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hotactio.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hotpatch.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\htlog.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\htpatch.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hwpe.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hxdl.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hxiul.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamapp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamserv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamstats.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ibmasn.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ibmavsp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\icload95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\icloadnt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\icmon.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\icsupp95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\icsuppnt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Identity.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\idle.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iedll.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iedriver.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IEShow.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iface.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ifw2000.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\inetlnfo.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\infus.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\infwin.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\init.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\init32.exe \Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[1].exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[2].exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[3].exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[4].exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[5].exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\intdel.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\intren.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iomon98.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\istsvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jammer.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jdbgmrg.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jedi.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\JsRcGen.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavlite40eng.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavpers40eng.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavpf.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kazza.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\keenvalue.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-pf-213-en-win.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-wrl-421-en-win.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-wrp-421-en-win.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\killprocesssetup161.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldnetmon.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldpro.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldpromenu.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldscan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\licmgr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\livesrv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lnetinfo.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\loader.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\localnet.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lockdown.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lockdown2000.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lookout.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lordpe.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lsetup.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\luall.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\luau.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lucomserver.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\luinit.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\luspt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MalwareRemoval.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mapisvc32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcagent.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcmnhdlr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcmscsvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcnasvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcproxy.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\McSACore.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcshell.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcshield.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcsysmon.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mctool.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcupdate.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcvsrte.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcvsshld.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\md.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfin32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfw2en.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfweng3.02d30.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgavrtcl.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgavrte.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mghtml.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgui.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\minilog.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmod.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\monitor.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\moolive.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpfagent.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpfservice.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MPFSrv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpftray.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mrflux.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mrt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msa.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msapp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msbb.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msblast.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscache.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msccn32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscman.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msdm.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msdos.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msfwsvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msiexec16.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mslaugh.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmgt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MsMpEng.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmsgri32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mssmmc32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mssys.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msvxd.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mu0311ad.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mwatch.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\n32scanw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nav.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\navap.navapsvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\navapsvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\navapw32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\navdx.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\navlu32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\navnt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\navstub.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\navw32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\navwnt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nc2000.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ncinst4.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ndd32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\neomonitor.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\neowatchlog.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\netarmor.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\netd32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\netinfo.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\netmon.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\netscanpro.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\netspyhunter-1.2.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\netutils.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nisserv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nisum.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nmain.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\normist.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\norton_internet_secu_3.0_407.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\notstart.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\npf40_tw_98_nt_me_2k.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\npfmessenger.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nprotect.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\npscheck.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\npssvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nsched32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nssys32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nstask32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nsupdate.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntrtscan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntvdm.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntxconfig.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nui.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nupgrade.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvarch16.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvc95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvsvc32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwinst4.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwservice.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwtool16.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAcat.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAhlp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAReg.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\oasrv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\oaui.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\oaview.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OcHealthMon.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ODSW.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ollydbg.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OLT.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onsrvr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\optimize.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ostronet.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\otfix.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpost.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpostinstall.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpostproinstall.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ozn695m5.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\padmin.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\panixk.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\patch.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pav.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavcl.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PavFnSvr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavproxy.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavprsrv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavsched.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavsrv51.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pccwin98.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcfwallicon.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcip10117_0.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcscan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsAuxs.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsGui.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsSvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsTray.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PC_Antispyware2010.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfndr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdsetup.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PerAvir.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\periscope.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\persfw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\perswf.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pf2.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pfwadmin.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pgmonitr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pingscan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pop3trap.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\poproxy.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\popscan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\portdetective.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\portmonitor.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerscan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ppinupdt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pptbc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ppvstop.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\prizesurfer.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\prmt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\prmvr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\procdump.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\processmonitor.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexplorerv1.0.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\programauditor.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\proport.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protector.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectx.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANCU.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANHost.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANToManager.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PsCtrls.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PsImSvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PskSvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pspf.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSUNMain.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\purge.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qconsole.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qh.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qserver.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quick Heal.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QuickHealCleaner.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rapapp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav7.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav7win.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav8win32eng.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ray.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rb32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rcsync.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\realmon.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\reged.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedt32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rescue.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rescue32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rrguard.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rscdwld.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rshell.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rtvscan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rtvscn95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rulaunch.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeweb.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sahagent.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Save.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveArmor.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveDefense.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveKeep.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\savenow.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sbserv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scam32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scanpm.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scrscan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\seccenter.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secure Veteran.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\secureveteran.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Security Center.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SecurityFighter.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\securitysoldier.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\serv95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setloadorder.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setupvameeval.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup_flowprotector_us.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sgssfw32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sh.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shellspyinstall.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shield.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shn.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\showbehind.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\signcheck.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smart.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartprotector.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smrtdefp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sms.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smss32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snetcfg.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\soap.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sofi.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftSafeness.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sperm.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spf.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sphinx.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoler.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolcv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolsv32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spywarexpguard.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spyxx.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\srexe.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\srng.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ss3edit.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssgrate.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssg_4104.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\st2.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\start.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stcloader.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\supftrl.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\support.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\supporter5.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchostc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchosts.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svshost.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweep95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweepnet.sweepsrv.sys.swnetsup.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcsvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\symproxysvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\symtray.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\system.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\system32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sysupd.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taumon.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbscan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tca.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tcm.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds-3.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds2-98.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds2-nt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\teekids.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tfak.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tfak5.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tgbob.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\titanin.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\titaninxp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TPSrv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\trickler.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\trjscan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\trjsetup.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\trojantrap3.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrustWarrior.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsadbot.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tvmd.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tvtmd.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uiscan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\undoboot.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\updat.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\upgrad.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\upgrepl.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utpost.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbcmserv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbcons.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbust.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbwin9x.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbwinntw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vcsetup.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vet32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vet95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vettray.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vfsetup.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vir-help.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\virusmdpersonalfirewall.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthAux.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthLic.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthUpd.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vnlan300.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vnpc3000.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpc32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpc42.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpfw30s.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vptray.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vscan40.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vscenu6.02d30.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsched.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsecomr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vshwin32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsisetup.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsmain.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsmon.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsserv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsstat.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswin9xe.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswinntse.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswinperse.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\w32dsm89.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\W3asbas.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\w9x.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\watchdog.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\webdav.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WebProxy.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\webscanx.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\webtrap.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wfindv32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\whoswatchingme.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wimmun32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\win-bugsfix.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\win32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\win32us.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winactive.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winav.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\windll32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\window.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows Police Pro.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wininetd.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wininitx.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winlogin.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winmain.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winppr32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winrecon.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winservn.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winss.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winssk32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winssnotify.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WinSSUI.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winstart.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winstart001.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wintsk32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winupdate.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wkufind.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wnad.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wnt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wradmin.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wrctrl.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsbgate.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxas.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxav.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxfw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsctool.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wupdater.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wupdt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wyvernworksfirewall.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpdeluxe.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpf202en.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapro.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zatutor.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zonalm2601.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zonealarm.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpm.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\~1.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\~2.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\URL: &#8220;http://findgala.com/?&amp;uid=231&amp;q={searchTerms}&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\URL: &#8220;http://findgala.com/?&amp;uid=231&amp;q={searchTerms}&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes\URL: &#8220;http://findgala.com/?&amp;uid=231&amp;q={searchTerms}&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\URL: &#8220;http://findgala.com/?&amp;uid=231&amp;q={searchTerms}&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes\URL: &#8220;http://findgala.com/?&amp;uid=231&amp;q={searchTerms}&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IIL: 0&#215;00000000</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\ltHI: 0&#215;00000000</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\ltTST: 0x0000F36B</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PRS: &#8220;http://127.0.0.1:27777/?inj=%ORIGINAL%&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\RunInvalidSignatures: 0&#215;00000001</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation\MSCompatibilityMode: 0&#215;00000000</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\URL: &#8220;http://findgala.com/?&amp;uid=231&amp;q={searchTerms}&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun: 0&#215;00000001</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\0: &#8220;msseces.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\1: &#8220;MSASCui.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\2: &#8220;ekrn.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\3: &#8220;egui.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\4: &#8220;avgnt.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\5: &#8220;avcenter.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\6: &#8220;avscan.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\7: &#8220;avgfrw.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\8: &#8220;avgui.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\9: &#8220;avgtray.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\10: &#8220;avgscanx.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\11: &#8220;avgcfgex.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\12: &#8220;avgemc.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\13: &#8220;avgchsvx.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\14: &#8220;avgcmgr.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\15: &#8220;avgwdsvc.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Home Safety Essentials: &#8220;&#8221;%AllUsersProfile%\Application Data\73f1ad\HS73f_231.exe&#8221; /s /d&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.HomeSafetyEssentials_1.png"><img class="alignnone size-medium wp-image-2558" title="Adware.Win32.HomeSafetyEssentials" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.HomeSafetyEssentials_1-400x202.png" alt="Adware.Win32.HomeSafetyEssentials" width="400" height="202" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.HomeSafetyEssentials_2.png"><img class="alignnone size-medium wp-image-2559" title="Adware.Win32.HomeSafetyEssentials" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.HomeSafetyEssentials_2-400x290.png" alt="Adware.Win32.HomeSafetyEssentials" width="400" height="290" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.HomeSafetyEssentials_3.png"><img class="alignnone size-medium wp-image-2560" title="Adware.Win32.HomeSafetyEssentials" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.HomeSafetyEssentials_3-400x290.png" alt="Adware.Win32.HomeSafetyEssentials" width="400" height="290" /></a></p>
<p><strong>How to remove the infection of </strong><strong>Home Safety Essentials </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HomeSafetyEssentials" target="_blank">Adware.Win32.HomeSafetyEssentials</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Smart Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/12/26/home-security-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Home Security Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/03/22/cleanup-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">CleanUP Antivirus Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/08/19/home-safety-essentials-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>System Repair Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/08/19/system-repair-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/08/19/system-repair-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 19 Aug 2011 21:02:33 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Defragmenter]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[FakeSysDef]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[System Repair]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2546</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the System Repair adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.SystemRepair. System Repair is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>System Repair </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.SystemRepair" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRepair" target="_blank"><strong>Adware.Win32.SystemRepair</strong></a><strong>.</strong></p>
<p><strong>System Repair</strong><strong> </strong><strong></strong>is             a                                          rogue                     application. A           rogue                             application               tries       to         trick  you   by                                                        displaying                                  false                                                      positive or misleading                  scan                                        results                                  report,      which         says                           that    your                                                                   computer            has    a              problem,                or           infected           with                                            viruses              or                      trojan,            but          you           will                          not                be           able                    to     fix         it                     before          you                                     purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfiles%\Application Data\~%random%r</li>
<li>%AllUsersProfiles%\Application Data\%random%.exe</li>
<li>%AllUsersProfiles%\Application Data\%random%</li>
<li>%AllUsersProfiles%\Application Data\~%random%</li>
<li>%UserProfile%\Desktop\System Repair.lnk</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\4\</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\1\</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\2\</li>
<li>%UserProfile%\Start Menu\Programs\System Repair\</li>
<li>%UserProfile%\Start Menu\Programs\System Repair\System Repair.lnk</li>
<li>%UserProfile%\Start Menu\Programs\System Repair\Uninstall System Repair.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\<br />
DisableTaskMgr: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\<br />
75fa38b7-8b94-4995-ad32-52e938867954:<br />
BD: 43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 74 00 73 00 20 00 61 00…</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\<br />
Use FormSuggest: “Yes”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\<br />
WarnonBadCertRecving: 0×00000000<br />
CertificateRevocation: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\<br />
NoChangingWallPaper: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\<br />
LowRiskFileTypes:     “/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\<br />
SaveZoneInformation: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
%random%: “%AllUsersProfile%\Application Data\%random%.exe”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures: “no”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
Hidden: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
ShowSuperHidden: 0×00000000</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.SystemRepair_1.png"><img class="alignnone size-medium wp-image-2547" title="Adware.Win32.SystemRepair" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.SystemRepair_1-400x104.png" alt="Adware.Win32.SystemRepair" width="400" height="104" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.SystemRepair_2.png"><img class="alignnone size-medium wp-image-2548" title="Adware.Win32.SystemRepair" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.SystemRepair_2-400x79.png" alt="Adware.Win32.SystemRepair" width="400" height="79" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.SystemRepair_3.png"><img class="alignnone size-medium wp-image-2549" title="Adware.Win32.SystemRepair" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.SystemRepair_3-400x240.png" alt="Adware.Win32.SystemRepair" width="400" height="240" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.SystemRepair_4.png"><img class="alignnone size-medium wp-image-2550" title="Adware.Win32.SystemRepair" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.SystemRepair_4-400x240.png" alt="Adware.Win32.SystemRepair" width="400" height="240" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.SystemRepair_5.png"><img class="alignnone size-medium wp-image-2551" title="Adware.Win32.SystemRepair" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.SystemRepair_5-400x240.png" alt="Adware.Win32.SystemRepair" width="400" height="240" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.SystemRepair_6.png"><img class="alignnone size-medium wp-image-2552" title="Adware.Win32.SystemRepair" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.SystemRepair_6-400x240.png" alt="Adware.Win32.SystemRepair" width="400" height="240" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.SystemRepair_7.png"><img class="alignnone size-medium wp-image-2553" title="Adware.Win32.SystemRepair" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.SystemRepair_7-400x218.png" alt="Adware.Win32.SystemRepair" width="400" height="218" /></a></p>
<p>To register and uninstall this rogue application, you can try one of the following serial number, and enter any email:</p>
<pre><span style="color: #ff0000;"><strong>1203978628012489708290478989147</strong>
<strong>8475082234984902023718742058948</strong></span></pre>
<p><strong>How to remove the infection of </strong><strong>System Repair </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRepair" target="_blank">Adware.Win32.SystemRepair</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/08/29/pc-repair-adware-removal-instructions/" rel="bookmark" class="crp_title">PC Repair Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/26/hdd-repair-adware-removal-instructions/" rel="bookmark" class="crp_title">HDD Repair Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/system-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">System Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/03/data-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/09/15/data-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Recovery Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/08/19/system-repair-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Protection Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/08/19/security-protection-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/08/19/security-protection-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 19 Aug 2011 14:54:33 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Security Protection]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2539</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Security Protection adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.SecurityProtection. Security Protection is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Security Protection</strong><strong> </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.SecurityProtection" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecurityProtection" target="_blank"><strong>Adware.Win32.SecurityProtection</strong></a><strong>.</strong></p>
<p><strong>Security Protection</strong><strong> </strong><strong></strong>is            a                                          rogue                    application. A           rogue                            application               tries       to         trick  you   by                                                       displaying                                 false                                                     positive or misleading                  scan                                       results                                  report,     which         says                           that    your                                                                  computer           has    a              problem,                or           infected          with                                            viruses             or                      trojan,            but          you          will                          not                be           able                   to     fix         it                     before         you                                     purchase.</p>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Security Protection: &#8220;%path%\defender.exe&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/SecurityProtection_1.png"><img class="alignnone size-medium wp-image-2540" title="Security Protection" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/SecurityProtection_1-400x294.png" alt="Security Protection" width="400" height="294" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/SecurityProtection_2.png"><img class="alignnone size-medium wp-image-2541" title="Security Protection" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/SecurityProtection_2-400x386.png" alt="Security Protection" width="400" height="386" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/SecurityProtection_3.png"><img class="alignnone size-medium wp-image-2542" title="Security Protection" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/SecurityProtection_3-400x193.png" alt="Security Protection" width="400" height="193" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/SecurityProtection_4.png"><img class="alignnone size-full wp-image-2543" title="Security Protection" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/SecurityProtection_4.png" alt="Security Protection" width="379" height="305" /></a></strong></p>
<p><strong>How to remove the infection of Security Protection </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecurityProtection"><strong>Adware.Win32.SecurityProtection</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/11/07/privacy-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Privacy Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Security 2012 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/23/av-protection-2011-rogue-removal-instructions/" rel="bookmark" class="crp_title">AV Protection 2011 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">System Security 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/19/av-protection-online-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Protection Online Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/08/19/security-protection-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>XP Home Security 2012 Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/08/19/xp-home-security-2012-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/08/19/xp-home-security-2012-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 19 Aug 2011 12:56:12 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Fake AV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Trojan.Win32.MultiFakeAV]]></category>
		<category><![CDATA[Win 7 Security 2012]]></category>
		<category><![CDATA[XP Home Security 2012]]></category>
		<category><![CDATA[XP Security 2012]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2533</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the XP Home Security 2012 adware. Emsisoft Anti-Malware detects this malware as Trojan.Win32.MultiFakeAV. XP Home Security 2012 is a rogue application. This rogue scanner able to change their name automatically depend on the Operating System, such as Win 7 Security 2012, XP Security 2012, [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <a title="XP Home Security 2012" href="http://www.emsisoft.com/en/malware/?Adware.Win32.XPHomeSecurity2012" target="_blank"><strong>XP Home Security 2012</strong></a><strong> </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <strong>Trojan.Win32.MultiFakeAV</strong><strong>.</strong></p>
<p><strong>XP Home Security 2012</strong><strong> </strong><strong></strong>is            a                                          rogue                    application. This rogue scanner able to change their name automatically depend on the Operating System, such as <strong>Win 7 Security 2012</strong>, <strong>XP Security 2012</strong>, etc. A           rogue                            application               tries       to         trick  you   by                                                       displaying                                 false                                                     positive/misleading                  scan                                       results                                  report,     which         says                           that    your                                                                  computer           has    a              problem,                or           infected          with                                            viruses             or                      trojan,            but          you          will                          not                be           able                   to     fix         it                     before         you                                     purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\58c6oqb2mq8eoqvwqxnno</li>
<li>%UserProfile%\Local Settings\Application Data\nqe.exe</li>
<li>%UserProfile%\Local Settings\Application Data\58c6oqb2mq8eoqvwqxnno</li>
<li>%UserProfile%\Local Settings\Temp\58c6oqb2mq8eoqvwqxnno</li>
<li>%UserProfile%\Templates\58c6oqb2mq8eoqvwqxnno</li>
</ul>
<p><strong>Create/modify new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile<br />
(DWORD) EnableFirewall = 0&#215;00000000 (0)<br />
(DWORD) DoNotAllowExceptions = 0&#215;00000000 (0)<br />
(DWORD) DisableNotifications = 0&#215;00000001 (1)</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile<br />
(DWORD) DoNotAllowExceptions = 0&#215;00000000 (0)<br />
(DWORD) DisableNotifications = 0&#215;00000001 (1)</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Clients\StartMenuInternet<br />
(String) (Default) = IEXPLORE.EXE</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run<br />
(String) 2260413329 = %UserProfile%\Local Settings\Application Data\nqe.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command<br />
(String) (Default) = &#8220;%UserProfile%\Local Settings\Application Data\nqe.exe&#8221; -a &#8220;C:\Program Files\Mozilla Firefox\firefox.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command<br />
(String) (Default) = &#8220;%UserProfile%\Local Settings\Application Data\nqe.exe&#8221; -a &#8220;C:\Program Files\Mozilla Firefox\firefox.exe&#8221; -safe-mode</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command<br />
(String) (Default) = &#8220;%UserProfile%\Local Settings\Application Data\nqe.exe&#8221; -a &#8220;C:\Program Files\Internet Explorer\iexplore.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Security Center<br />
(DWORD) AntiVirusDisableNotify = 0&#215;00000001 (1)<br />
(DWORD) AntiVirusOverride = 0&#215;00000001 (1)<br />
(DWORD) FirewallDisableNotify = 0&#215;00000001 (1)<br />
(DWORD) FirewallOverride = 0&#215;00000001 (1)<br />
(DWORD) UpdatesDisableNotify = 0&#215;00000001 (1)</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess<br />
(DWORD) Start = 0&#215;00000004 (4)</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/XP-Home-Security-2012.png"><img class="alignnone size-medium wp-image-2535" title="XP Home Security 2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/XP-Home-Security-2012-400x285.png" alt="XP Home Security 2012" width="400" height="285" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/XP-Security-2012.png"><img class="alignnone size-medium wp-image-2536" title="XP Security 2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/XP-Security-2012-400x285.png" alt="XP Security 2012" width="400" height="285" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Win-7-Security-2012.png"><img class="alignnone size-medium wp-image-2534" title="Win 7 Security 2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Win-7-Security-2012-400x284.png" alt="Win 7 Security 2012" width="400" height="284" /></a></strong></p>
<p><strong>How to remove the infection of <a title="XP Home Security 2012" href="http://www.emsisoft.com/en/malware/?Adware.Win32.XPHomeSecurity2012" target="_blank">XP Home Security 2012</a> </strong><strong>(Trojan.Win32.MultiFakeAV</strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/11/29/xp-antivirus-2012-multifakeav-rogue-removal-instructions/" rel="bookmark" class="crp_title">XP Antivirus 2012 (MultiFakeAV) Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/22/xp-antispyware-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">XP AntiSpyware 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/23/internet-security-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/03/security-sphere-2012-removal-instructions/" rel="bookmark" class="crp_title">Security Sphere 2012 Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/11/23/win-7-antispyware-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">Win 7 Antispyware 2011 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/08/19/xp-home-security-2012-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wolfram Antivirus Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/08/13/wolfram-antivirus-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/08/13/wolfram-antivirus-adware-removal-instructions/#comments</comments>
		<pubDate>Sat, 13 Aug 2011 16:53:11 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Wolfram Antivirus]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2525</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Wolfram Antivirus adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WolframAntivirus. Wolfram Antivirus is a rogue application, this is another variant of BlueFlare Antivirus A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Wolfram Antivirus</strong><strong> </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.WolframAntivirus" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WolframAntivirus" target="_blank"><strong>Adware.Win32.WolframAntivirus</strong></a><strong>.</strong></p>
<p><strong>Wolfram Antivirus</strong><strong></strong><strong> </strong><strong></strong>is            a                                          rogue                    application, this is another variant of <a href="http://www.anti-malware-blog.com/2011/08/05/blueflare-antivirus-adware-removal-instructions/"><strong>BlueFlare Antivirus</strong></a> A           rogue                            application              tries       to         trick  you   by                                                      displaying                                 false                                                    positive/misleading                 scan                                       results                                 report,     which         says                          that    your                                                                 computer           has    a              problem,               or           infected          with                                           viruses             or                      trojan,           but          you          will                          not               be           able                   to     fix         it                    before         you                                     purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Wolfram Antivirus\</li>
<li>%UserProfile%\Application Data\Wolfram Antivirus\csrss.exe</li>
<li>%UserProfile%\Application Data\Wolfram Antivirus\wf.conf</li>
<li>%UserProfile%\Application Data\Wolfram Antivirus\Wolfram Antivirus.exe</li>
<li>%UserProfile%\Application Data\Wolfram Antivirus\Wolfram Antivirus.ico</li>
<li>%UserProfile%\Desktop\Wolfram Antivirus.lnk</li>
<li>%UserProfile%\Local Settings\Temp\1.tmp</li>
<li>%UserProfile%\Start Menu\Programs\Startup\csrss.exe</li>
<li>%UserProfile%\Start Menu\Programs\Wolfram Antivirus\Wolfram Antivirus.lnk</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.WolframAntivirus_1.png"><img class="alignnone size-medium wp-image-2526" title="Adware.Win32.WolframAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.WolframAntivirus_1-400x301.png" alt="Adware.Win32.WolframAntivirus" width="400" height="301" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.WolframAntivirus_2.png"><img class="alignnone size-medium wp-image-2527" title="Adware.Win32.WolframAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.WolframAntivirus_2-400x334.png" alt="Adware.Win32.WolframAntivirus" width="400" height="334" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.WolframAntivirus_3.png"><img class="alignnone size-medium wp-image-2528" title="Adware.Win32.WolframAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.WolframAntivirus_3-400x251.png" alt="Adware.Win32.WolframAntivirus" width="400" height="251" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.WolframAntivirus_4.png"><img class="alignnone size-medium wp-image-2529" title="Adware.Win32.WolframAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.WolframAntivirus_4-400x210.png" alt="Adware.Win32.WolframAntivirus" width="400" height="210" /></a></strong></p>
<p><strong>How to remove the infection of Wolfram Antivirus </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WolframAntivirus"><strong>Adware.Win32.WolframAntivirus</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/08/05/blueflare-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">BlueFlare Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/29/opencloud-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">OpenCloud Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/08/antivirus-antispyware-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">AntiVirus AntiSpyware 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/04/13/antivirus-clean-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Clean 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/08/13/wolfram-antivirus-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Zentom System Guard Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/08/05/zentom-system-guard-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/08/05/zentom-system-guard-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 05 Aug 2011 12:57:39 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Zentom System Guard]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2517</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Zentom System Guard adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.ZentomSystemGuard. Zentom System Guard is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Zentom System Guard</strong><strong> </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.ZentomSystemGuard" href="http://www.emsisoft.com/en/malware/?Adware.Win32.ZentomSystemGuard" target="_blank"><strong>Adware.Win32.ZentomSystemGuard</strong></a><strong>.</strong></p>
<p><strong>Zentom System Guard</strong><strong> </strong><strong> </strong><strong> </strong>is            a                                          rogue                    application.                                                                          A           rogue                            application              tries       to         trick  you   by                                                      displaying                                 false                                                    positive/misleading                 scan                                       results                                 report,     which         says                          that    your                                                                 computer           has    a              problem,               or           infected          with                                           viruses             or                      trojan,           but          you          will                          not               be           able                   to     fix         it                    before         you                                     purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%UserProfile%\Application Data\8E833AF3E1E0916F560FF368E03665CE\enemies-names.txt</li>
<li> %UserProfile%\Application Data\8E833AF3E1E0916F560FF368E03665CE\hookdll.dll</li>
<li> %UserProfile%\Application Data\8E833AF3E1E0916F560FF368E03665CE\local.ini</li>
<li> %UserProfile%\Application Data\8E833AF3E1E0916F560FF368E03665CE\lsrslt.ini</li>
<li> %UserProfile%\Application Data\8E833AF3E1E0916F560FF368E03665CE\onslik700patch.exe</li>
<li> %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Zentom System Guard.lnk</li>
<li> %UserProfile%\Desktop\Zentom System Guard.lnk</li>
<li> %UserProfile%\Start Menu\Zentom System Guard.lnk</li>
<li> %UserProfile%\Start Menu\Programs\Startup\Zentom System Guard.lnk</li>
<li> %UserProfile%\Start Menu\Programs\Zentom System Guard\Uninstall.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Zentom System Guard\Zentom System Guard.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run<br />
(String) onslik700patch.exe = &#8220;%UserProfile%\Application Data\8E833AF3E1E0916F560FF368E03665CE\onslik700patch.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Uninstall\Zentom System Guard<br />
(String) DisplayIcon = %UserProfile%\Application Data\8E833AF3E1E0916F560FF368E03665CE\onslik700patch.exe,0<br />
(String) DisplayName = Zentom System Guard<br />
(String) UninstallString = %UserProfile%\Application Data\8E833AF3E1E0916F560FF368E03665CE\onslik700patch.exe /uninstall<br />
(String) InstallLocation = %UserProfile%\Application Data\8E833AF3E1E0916F560FF368E03665CE\<br />
(DWORD) NoModify = 0&#215;00000001 (1)<br />
(DWORD) NoRepair = 0&#215;00000001 (1)</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\ZentomSystemGuard\Zentom System Guard<br />
(String) datarl1 = KRoA&#8230;<br />
(String) datarl2 = KRoA&#8230;<br />
(String) datarlA = KRoA&#8230;<br />
(String) install_time = 8/4/2011 8:48:44 PM<br />
(String) database_version = 257<br />
(String) virus_signatures = 62731<br />
(String) inst = ok<br />
(String) coid = NjE4&#8230;<br />
(String) affid = 7070010200<br />
(String) nsaftscann = 1<br />
(String) nsa = 1<br />
(String) nsaftscanunp = 1</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.ZentomSystemGuard_1.png"><img class="alignnone size-medium wp-image-2518" title="Adware.Win32.ZentomSystemGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.ZentomSystemGuard_1-400x298.png" alt="Adware.Win32.ZentomSystemGuard" width="400" height="298" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.ZentomSystemGuard_2.png"><img class="alignnone size-medium wp-image-2519" title="Adware.Win32.ZentomSystemGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.ZentomSystemGuard_2-400x271.png" alt="Adware.Win32.ZentomSystemGuard" width="400" height="271" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.ZentomSystemGuard_3.png"><img class="alignnone size-medium wp-image-2520" title="Adware.Win32.ZentomSystemGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.ZentomSystemGuard_3-400x272.png" alt="Adware.Win32.ZentomSystemGuard" width="400" height="272" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.ZentomSystemGuard_4.png"><img class="alignnone size-medium wp-image-2521" title="Adware.Win32.ZentomSystemGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.ZentomSystemGuard_4-400x331.png" alt="Adware.Win32.ZentomSystemGuard" width="400" height="331" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.ZentomSystemGuard_5.png"><img class="alignnone size-medium wp-image-2522" title="Adware.Win32.ZentomSystemGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.ZentomSystemGuard_5-400x201.png" alt="Adware.Win32.ZentomSystemGuard" width="400" height="201" /></a></p>
<p><strong>How to remove the infection of Zentom System Guard </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.ZentomSystemGuard"><strong>Adware.Win32.ZentomSystemGuard</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/09/09/malware-destructor-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">Malware Destructor 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">System Security 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/11/08/system-tool-adware-removal-instructions/" rel="bookmark" class="crp_title">System Tool Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/11/11/security-inspector-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Inspector 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/06/security-guard-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Guard 2012 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/08/05/zentom-system-guard-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BlueFlare Antivirus Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/08/05/blueflare-antivirus-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/08/05/blueflare-antivirus-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 05 Aug 2011 12:47:04 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[BlueFlare Antivirus]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2512</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the BlueFlare Antivirus adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.BlueFlareAntivirus. BlueFlare Antivirus is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with viruses or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>BlueFlare Antivirus</strong><strong> </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.BlueFlareAntivirus" href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlueFlareAntivirus" target="_blank"><strong>Adware.Win32.BlueFlareAntivirus</strong></a><strong>.</strong></p>
<p><strong>BlueFlare Antivirus</strong><strong></strong><strong> </strong><strong></strong>is           a                                          rogue                   application.                                                                         A           rogue                           application              tries       to         trick  you   by                                                     displaying                                false                                                   positive/misleading                 scan                                      results                                 report,     which        says                          that    your                                                                computer           has    a             problem,               or           infected          with                                          viruses             or                     trojan,           but          you          will                         not               be           able                   to     fix        it                    before         you                                    purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%UserProfile%\Application Data\BlueFlare Antivirus\BlueFlare Antivirus.exe</li>
<li> %UserProfile%\Application Data\BlueFlare Antivirus\BlueFlare Antivirus.ico</li>
<li> %UserProfile%\Application Data\BlueFlare Antivirus\csrss.exe</li>
<li> %UserProfile%\Application Data\BlueFlare Antivirus\ms.conf</li>
<li> %UserProfile%\Desktop\BlueFlare Antivirus.lnk</li>
<li> %UserProfile%\Local Settings\Temp\1.tmp</li>
<li> %UserProfile%\Start Menu\Programs\BlueFlare Antivirus\BlueFlare Antivirus.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Startup\csrss.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.BlueFlareAntivirus_1.png"><img class="alignnone size-medium wp-image-2513" title="Adware.Win32.BlueFlareAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.BlueFlareAntivirus_1-400x301.png" alt="Adware.Win32.BlueFlareAntivirus" width="400" height="301" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.BlueFlareAntivirus_2.png"><img class="alignnone size-medium wp-image-2514" title="Adware.Win32.BlueFlareAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.BlueFlareAntivirus_2-400x334.png" alt="Adware.Win32.BlueFlareAntivirus" width="400" height="334" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.BlueFlareAntivirus_3.png"><img class="alignnone size-medium wp-image-2515" title="Adware.Win32.BlueFlareAntivirus" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/08/Adware.Win32.BlueFlareAntivirus_3-400x251.png" alt="Adware.Win32.BlueFlareAntivirus" width="400" height="251" /></a></p>
<p><strong>How to remove the infection of BlueFlare Antivirus </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BlueFlareAntivirus"><strong>Adware.Win32.BlueFlareAntivirus</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/08/13/wolfram-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">Wolfram Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/29/opencloud-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">OpenCloud Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/08/antivirus-antispyware-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">AntiVirus AntiSpyware 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/04/13/antivirus-clean-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Clean 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/11/rts-antivirus-2010-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">RTS Antivirus 2010 Pro Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/08/05/blueflare-antivirus-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Armour Master Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/07/24/windows-armour-master-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/07/24/windows-armour-master-adware-removal-instructions/#comments</comments>
		<pubDate>Sun, 24 Jul 2011 02:55:07 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Armour Master]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2501</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Armour Master adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsArmourMaster. Windows Armour Master is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with viruses [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Armour Master</strong><strong> </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.WindowsArmourMaster" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsArmatureMaster" target="_blank"><strong>Adware.Win32.WindowsArmourMaster</strong></a><strong>.</strong></p>
<p><strong></strong><strong>Windows Armour Master</strong><strong> </strong><strong></strong>is          a                                          rogue                  application.                                                                        A           rogue                           application             tries       to         trick  you   by                                                    displaying                               false                                                  positive/misleading                 scan                                     results                                 report,     which       says                          that    your                                                               computer           has    a            problem,               or           infected          with                                         viruses             or                    trojan,           but          you          will                        not               be           able                   to     fix       it                    before         you                                   purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a title="Adware.Win32.WindowsArmatureMaster" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsArmatureMaster" target="_blank"><strong>Windows Armature Master</strong></a><strong></strong><a title="Adware.Win32.WindowsDebuggingAgent" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDebuggingAgent" target="_blank"><strong></strong></a></li>
<li><a title="Adware.Win32.WindowsDebuggingAgent" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDebuggingAgent" target="_blank"><strong>Windows Debugging Agent</strong></a></li>
<li><a title="Adware.Win32.WindowsAccurateProtector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccurateProtector" target="_blank"><strong>Windows Accurate Protector</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsVulnerabilitiesRescuer"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsVulnerabilitiesRescuer"><strong>Windows Vulnerabilities Rescuer</strong></a><strong></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTestMaster"><strong>Windows Test Master</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSalvorTool"><strong>Windows Salvor Tool</strong><strong> </strong><strong> </strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProofnessGuarantor">Windows Proofness Guarantor</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDebuggingCenter"><strong>Windows Debugging Center</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInviolabilitySystem"><strong>Windows Inviolability System</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVComponent"><strong>Windows AV Component</strong><strong> </strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntivirusSystem"><strong>Windows Antivirus System</strong></a><strong> </strong></li>
<li><strong> </strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispyNetwork"><strong>Windows Antispy Network</strong></a><strong> </strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong> Windows Antidanger Center</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong>Windows Accelerating Utility</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWorkChecker" target="_blank"><strong>Windows Work Checker</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMonitoringUtility"><strong> Windows Monitoring Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExaminationUtility"><strong>Windows Examination Utility</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesKiller"><strong>Windows Troubles Killer</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionAlarm"><strong>Windows Protection Alarm</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRescueCenter" target="_blank"><strong>Windows Rescue Center</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrashesDeliverer"><strong>Windows Crashes Deliverer</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSaviourFirewall"><strong>Windows Saviour Firewall</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAvertingSystem"><strong>Windows Averting System</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccidentsPrevention"><strong>Windows Accidents Prevention</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver"><strong>Windows Troubles Solver</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Windows Anticrashes Utility</strong></a></li>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong></strong><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Internet Settings<br />
(DWORD) WarnOnHTTPSToHTTPRedirect = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Internet Settings<br />
(DWORD) WarnOnHTTPSToHTTPRedirect = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\a.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aAvgApi.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AAWTray.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\About.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ackwin32.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Ad-Aware.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\adaware.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\advxdwin.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AdwarePrj.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agent.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agentsvr.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agentw.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alertsvc.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alevir.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alogserv.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AlphaAV<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AlphaAV.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AluSchedulerSvc.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\amon9x.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\anti-trojan.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Anti-Virus Professional.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntispywarXP2009.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\antivirus.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPlus<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPlus.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPro_2010.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusXP<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusXP.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\antivirusxppro2009.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntiVirus_Pro.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ants.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\apimonitor.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aplica32.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\apvxdwin.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\arr.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashAvast.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashBug.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashChest.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashCnsnt.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashDisp.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashLogV.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashMaiSv.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashPopWz.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashQuick.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashServ.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSimp2.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSimpl.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSkPcc.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSkPck.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashUpd.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashWebSv.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswChLic.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswRegSvr.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswRunDll.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswUpdSv.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atcon.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atguard.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atro55en.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atupdater.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atwatch.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\au.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aupdate.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\auto-protect.nav80try.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autodown.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autotrace.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autoupdate.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\av360.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avadmin.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVCare.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avcenter.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avciman.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avconfig.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avconsol.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ave32.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVENGINE.EXE<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcc32.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgchk.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcmgr.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcsrvx.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgctrl.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgdumpx.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgemc.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgiproxy.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgnsx.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgnt.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgrsx.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgscanx.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgserv.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgserv9.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgsrmax.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgtray.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgui.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgupd.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgw.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgwdsvc.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkpop.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkserv.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkservice.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkwctl9.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avltmain.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avmailc.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avmcdlg.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avnotify.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avnt.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avp32.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpcc.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpdos32.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpm.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avptc32.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpupd.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avsched32.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avsynmgr.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avupgsvc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVWEBGRD.EXE<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwin.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwin95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwinnt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwsc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupd.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupd32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupsrv.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxmonitor9x.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxmonitornt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxquar.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\b.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\backweb.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bargains.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdfvcl.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdfvwiz.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDInProcPatch.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdmcon.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDMsnScan.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDSurvey.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bd_professional.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\beagle.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\belt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bidef.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bidserver.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bipcp.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bipcpevalsetup.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bisp.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blackd.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blackice.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blink.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blss.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bootconf.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bootwarn.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\borg2.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bpc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brasil.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brastk.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brw.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bs120.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bspatch.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bundle.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bvt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\c.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cavscan.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccapp.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccevtmgr.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccpxysvc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccSvcHst.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cdp.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfd.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfgwiz.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfiadmin.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfiaudit.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfinet.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfinet32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfp.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfpconfg.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfplogvw.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfpupdat.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Cl.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\claw95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\claw95cf.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\clean.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleaner.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleaner3.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleanIELow.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleanpc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\click.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmd32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmdagent.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmesys.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmgrdian.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmon016.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\connectionmonitor.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\control<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpd.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpf9x206.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpfnt206.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\crashrep.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\csc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssconfg.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssupdat.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssurf.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ctrl.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cv.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cwnb181.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cwntdwmo.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\d.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\datemanager.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dcomx.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defalert.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defscangui.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defwatch.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\deloeminfs.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\deputy.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\divx.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dllcache.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dllreg.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\doors.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dop.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpf.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpfsetup.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpps2.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\driverctrl.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drwatson.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drweb32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drwebupw.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dssagent.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dvp95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dvp95_0.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ecengine.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\efpeadm.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\emsw.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ent.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\esafe.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\escanhnt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\escanv95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\espwatch.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ethereal.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\etrustcipe.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\evpn.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\exantivirus-cnet.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\exe.avxw.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\expert.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\explore.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-agnt95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-prot.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-prot95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-stopw.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fact.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fameh32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fast.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fch32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fih32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\findviru.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\firewall.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fixcfg.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fixfp.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fnrb32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fp-win.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fp-win_trial.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fprot.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\frmwrk32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\frw.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsaa.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav530stbyb.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav530wtbyb.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsgk32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsm32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsma32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsmb32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gator.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gav.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbmenu.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbn976rl.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbpoll.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\generics.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gmt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guard.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guarddog.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guardgui.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hacktracersetup.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hbinst.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hbsrv.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\History.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\homeav2010.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hotactio.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hotpatch.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\htlog.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\htpatch.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hwpe.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hxdl.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hxiul.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamapp.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamserv.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamstats.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ibmasn.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ibmavsp.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icload95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icloadnt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icmon.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icsupp95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icsuppnt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Identity.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\idle.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iedll.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iedriver.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\IEShow.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iface.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ifw2000.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\inetlnfo.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\infus.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\infwin.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\init.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\init32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\install[1].exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\install[2].exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\install[3].exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\install[4].exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\install[5].exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\intdel.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\intren.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iomon98.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\istsvc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jammer.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jdbgmrg.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jedi.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\JsRcGen.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavlite40eng.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavpers40eng.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavpf.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kazza.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\keenvalue.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-pf-213-en-win.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-wrl-421-en-win.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-wrp-421-en-win.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\killprocesssetup161.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldnetmon.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldpro.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldpromenu.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldscan.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\licmgr.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lnetinfo.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\loader.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\localnet.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lockdown.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lockdown2000.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lookout.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lordpe.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lsetup.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luall.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luau.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lucomserver.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luinit.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luspt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MalwareRemoval.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mapisvc32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcagent.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcmnhdlr.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcmscsvc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcnasvc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcproxy.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\McSACore.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcshell.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcshield.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcsysmon.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mctool.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcupdate.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcvsrte.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcvsshld.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\md.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfin32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfw2en.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfweng3.02d30.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgavrtcl.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgavrte.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mghtml.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgui.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\minilog.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mmod.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\monitor.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\moolive.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mostat.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpfagent.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpfservice.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MPFSrv.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpftray.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mrflux.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mrt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msa.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msapp.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MSASCui.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msbb.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msblast.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mscache.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msccn32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mscman.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msconfig<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msdm.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msdos.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msiexec16.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mslaugh.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmgt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmsgri32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mssmmc32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mssys.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msvxd.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mu0311ad.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mwatch.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\n32scanw.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nav.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navap.navapsvc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navapsvc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navapw32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navdx.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navlu32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navnt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navstub.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navw32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navwnt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nc2000.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ncinst4.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ndd32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\neomonitor.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\neowatchlog.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netarmor.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netd32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netinfo.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netmon.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netscanpro.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netspyhunter-1.2.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netutils.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nisserv.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nisum.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nmain.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nod32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\normist.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\norton_internet_secu_3.0_407.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\notstart.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npf40_tw_98_nt_me_2k.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npfmessenger.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nprotect.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npscheck.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npssvc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nsched32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nssys32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nstask32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nsupdate.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntrtscan.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntvdm.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntxconfig.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nui.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nupgrade.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvarch16.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvc95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvsvc32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwinst4.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwservice.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwtool16.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAcat.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAhlp.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAReg.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oasrv.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oaui.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oaview.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ODSW.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ollydbg.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\onsrvr.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\optimize.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ostronet.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\otfix.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpost.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpostinstall.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpostproinstall.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ozn695m5.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\padmin.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\panixk.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\patch.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pav.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavcl.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PavFnSvr.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavproxy.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavprsrv.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavsched.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavsrv51.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavw.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pccwin98.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcfwallicon.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcip10117_0.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcscan.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsAuxs.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsGui.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsSvc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsTray.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PC_Antispyware2010.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pdfndr.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pdsetup.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PerAvir.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\periscope.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\persfw.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\personalguard<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\personalguard.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\perswf.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pf2.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pfwadmin.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pgmonitr.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pingscan.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\platin.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pop3trap.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\poproxy.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\popscan.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\portdetective.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\portmonitor.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\powerscan.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ppinupdt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pptbc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ppvstop.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prizesurfer.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prmt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prmvr.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\procdump.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\processmonitor.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\procexplorerv1.0.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\programauditor.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\proport.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\protector.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\protectx.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANCU.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANHost.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANToManager.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PsCtrls.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PsImSvc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PskSvc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pspf.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSUNMain.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\purge.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qconsole.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qh.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qserver.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Quick Heal.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\QuickHealCleaner.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rapapp.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav7.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav7win.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav8win32eng.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ray.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rb32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rcsync.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\realmon.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\reged.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\regedt32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rescue.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rescue32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rrguard.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rscdwld.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rshell.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rtvscan.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rtvscn95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rulaunch.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rwg<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rwg.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SafetyKeeper.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\safeweb.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sahagent.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Save.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveArmor.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveDefense.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveKeep.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\savenow.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sbserv.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scam32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scan32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scan95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scanpm.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scrscan.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Secure Veteran.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\secureveteran.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Security Center.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SecurityFighter.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\securitysoldier.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\serv95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setloadorder.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setupvameeval.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setup_flowprotector_us.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sgssfw32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sh.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shellspyinstall.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shield.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shn.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\showbehind.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\signcheck.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smart.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smartprotector.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smrtdefp.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sms.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smss32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\snetcfg.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\soap.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sofi.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SoftSafeness.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sperm.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spf.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sphinx.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoler.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoolcv.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoolsv32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spywarexpguard.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spyxx.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\srexe.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\srng.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ss3edit.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ssgrate.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ssg_4104.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\st2.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\start.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\stcloader.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\supftrl.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\support.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\supporter5.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svchostc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svchosts.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svshost.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sweep95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sweepnet.sweepsrv.sys.swnetsup.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symlcsvc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symproxysvc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symtray.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\system.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\system32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sysupd.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tapinstall.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\taumon.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tbscan.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tca.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tcm.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds-3.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds2-98.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds2-nt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\teekids.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tfak.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tfak5.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tgbob.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\titanin.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\titaninxp.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\TPSrv.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trickler.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trjscan.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trjsetup.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trojantrap3.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\TrustWarrior.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tsadbot.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tsc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tvmd.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tvtmd.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\undoboot.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\updat.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\upgrad.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\utpost.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbcmserv.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbcons.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbust.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbwin9x.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbwinntw.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vcsetup.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vet32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vet95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vettray.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vfsetup.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vir-help.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\virusmdpersonalfirewall.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthAux.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthLic.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthUpd.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vnlan300.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vnpc3000.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpc32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpc42.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpfw30s.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vptray.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vscan40.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vscenu6.02d30.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsched.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsecomr.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vshwin32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsisetup.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsmain.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsmon.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsstat.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswin9xe.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswinntse.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswinperse.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\w32dsm89.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\W3asbas.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\w9x.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\watchdog.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webdav.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\WebProxy.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webscanx.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webtrap.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wfindv32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\whoswatchingme.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wimmun32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win-bugsfix.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win32us.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winactive.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winav.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windll32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\window.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windows Police Pro.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windows.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wininetd.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wininitx.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winlogin.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winmain.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winppr32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winrecon.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winservn.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winssk32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winstart.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winstart001.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wintsk32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winupdate.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wkufind.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wnad.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wnt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wradmin.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wrctrl.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wsbgate.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxas.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxav.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxfw.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wsctool.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wupdater.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wupdt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wyvernworksfirewall.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xpdeluxe.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xpf202en.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xp_antispyware.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zapro.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zapsetup3001.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zatutor.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zonalm2601.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zonealarm.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avp32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avpcc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avpm.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\~1.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\~2.exe<br />
(SZ)Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmourMaster_1.png"><img class="alignnone size-medium wp-image-2502" title="Adware.Win32.WindowsArmourMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmourMaster_1-400x208.png" alt="Adware.Win32.WindowsArmourMaster" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmourMaster_2.png"><img class="alignnone size-medium wp-image-2503" title="Adware.Win32.WindowsArmourMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmourMaster_2-400x208.png" alt="Adware.Win32.WindowsArmourMaster" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmourMaster_3.png"><img class="alignnone size-medium wp-image-2504" title="Adware.Win32.WindowsArmourMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmourMaster_3-400x228.png" alt="Adware.Win32.WindowsArmourMaster" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmourMaster_4.png"><img class="alignnone size-medium wp-image-2505" title="Adware.Win32.WindowsArmourMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmourMaster_4-400x235.png" alt="Adware.Win32.WindowsArmourMaster" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmourMaster_5.png"><img class="alignnone size-medium wp-image-2506" title="Adware.Win32.WindowsArmourMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmourMaster_5-400x214.png" alt="Adware.Win32.WindowsArmourMaster" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmourMaster_6.png"><img class="alignnone size-medium wp-image-2507" title="Adware.Win32.WindowsArmourMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmourMaster_6-400x214.png" alt="Adware.Win32.WindowsArmourMaster" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmourMaster_7.png"><img class="alignnone size-medium wp-image-2508" title="Adware.Win32.WindowsArmourMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmourMaster_7-400x211.png" alt="Adware.Win32.WindowsArmourMaster" width="400" height="211" /></a></strong></p>
<p><strong>How to remove the infection of Windows Armour Master </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsArmourMaster"><strong>Adware.Win32.WindowsArmourMaster</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Smart Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/12/26/home-security-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Home Security Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/03/22/cleanup-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">CleanUP Antivirus Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/07/24/windows-armour-master-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Armature Master Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/07/24/windows-armature-master-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/07/24/windows-armature-master-adware-removal-instructions/#comments</comments>
		<pubDate>Sun, 24 Jul 2011 02:35:45 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Armature Master]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2486</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Armature Master adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsArmatureMaster. Windows Armature Master is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with viruses [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Armature Master</strong><strong> </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.WindowsArmatureMaster" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsArmatureMaster" target="_blank"><strong>Adware.Win32.WindowsArmatureMaster</strong></a><strong>.</strong></p>
<p><strong></strong><strong>Windows Armature Master</strong><strong> </strong><strong></strong>is         a                                          rogue                 application.                                                                       A           rogue                           application            tries       to         trick  you   by                                                   displaying                               false                                                 positive/misleading                scan                                     results                                report,     which       says                         that    your                                                              computer           has    a            problem,               or          infected          with                                        viruses             or                    trojan,           but         you          will                        not               be          able                   to     fix       it                    before        you                                   purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a title="Adware.Win32.WindowsDebuggingAgent" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDebuggingAgent" target="_blank"><strong>Windows Debugging Agent</strong></a></li>
<li><a title="Adware.Win32.WindowsAccurateProtector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccurateProtector" target="_blank"><strong>Windows Accurate Protector</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsVulnerabilitiesRescuer"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsVulnerabilitiesRescuer"><strong>Windows Vulnerabilities Rescuer</strong></a><strong></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTestMaster"><strong>Windows Test Master</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSalvorTool"><strong>Windows Salvor Tool</strong><strong> </strong><strong> </strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProofnessGuarantor">Windows Proofness Guarantor</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDebuggingCenter"><strong>Windows Debugging Center</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInviolabilitySystem"><strong>Windows Inviolability System</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVComponent"><strong>Windows AV Component</strong><strong> </strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntivirusSystem"><strong>Windows Antivirus System</strong></a><strong> </strong></li>
<li><strong> </strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispyNetwork"><strong>Windows Antispy Network</strong></a><strong> </strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong> Windows Antidanger Center</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong>Windows Accelerating Utility</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWorkChecker" target="_blank"><strong>Windows Work Checker</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMonitoringUtility"><strong> Windows Monitoring Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExaminationUtility"><strong>Windows Examination Utility</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesKiller"><strong>Windows Troubles Killer</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionAlarm"><strong>Windows Protection Alarm</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRescueCenter" target="_blank"><strong>Windows Rescue Center</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrashesDeliverer"><strong>Windows Crashes Deliverer</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSaviourFirewall"><strong>Windows Saviour Firewall</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAvertingSystem"><strong>Windows Averting System</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccidentsPrevention"><strong>Windows Accidents Prevention</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver"><strong>Windows Troubles Solver</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Windows Anticrashes Utility</strong></a></li>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong></strong><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Internet Settings<br />
(DWORD) WarnOnHTTPSToHTTPRedirect = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Internet Settings<br />
(DWORD) WarnOnHTTPSToHTTPRedirect = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\a.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aAvgApi.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AAWTray.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\About.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ackwin32.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Ad-Aware.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\adaware.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\advxdwin.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AdwarePrj.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agent.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agentsvr.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\agentw.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alertsvc.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alevir.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\alogserv.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AlphaAV<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AlphaAV.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AluSchedulerSvc.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\amon9x.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\anti-trojan.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Anti-Virus Professional.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntispywarXP2009.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\antivirus.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPlus<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPlus.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusPro_2010.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusXP<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntivirusXP.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\antivirusxppro2009.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AntiVirus_Pro.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ants.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\apimonitor.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aplica32.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\apvxdwin.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\arr.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashAvast.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashBug.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashChest.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashCnsnt.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashDisp.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashLogV.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashMaiSv.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashPopWz.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashQuick.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashServ.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSimp2.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSimpl.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSkPcc.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashSkPck.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashUpd.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ashWebSv.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswChLic.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswRegSvr.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswRunDll.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aswUpdSv.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atcon.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atguard.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atro55en.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atupdater.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\atwatch.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\au.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\aupdate.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\auto-protect.nav80try.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autodown.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autotrace.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\autoupdate.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\av360.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avadmin.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVCare.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avcenter.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avciman.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avconfig.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avconsol.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ave32.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVENGINE.EXE<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcc32.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgchk.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcmgr.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgcsrvx.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgctrl.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgdumpx.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgemc.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgiproxy.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgnsx.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgnt.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgrsx.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgscanx.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgserv.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgserv9.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgsrmax.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgtray.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgui.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgupd.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgw.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avgwdsvc.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkpop.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkserv.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkservice.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avkwctl9.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avltmain.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avmailc.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avmcdlg.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avnotify.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avnt.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avp32.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpcc.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpdos32.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpm.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avptc32.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avpupd.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avsched32.exe<br />
(SZ) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avsynmgr.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avupgsvc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\AVWEBGRD.EXE<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwin.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwin95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwinnt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwsc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupd.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupd32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avwupsrv.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxmonitor9x.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxmonitornt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avxquar.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\b.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\backweb.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bargains.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdfvcl.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdfvwiz.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDInProcPatch.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bdmcon.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDMsnScan.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\BDSurvey.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bd_professional.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\beagle.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\belt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bidef.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bidserver.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bipcp.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bipcpevalsetup.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bisp.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blackd.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blackice.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blink.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\blss.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bootconf.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bootwarn.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\borg2.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bpc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brasil.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brastk.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\brw.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bs120.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bspatch.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bundle.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\bvt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\c.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cavscan.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccapp.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccevtmgr.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccpxysvc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ccSvcHst.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cdp.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfd.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfgwiz.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfiadmin.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfiaudit.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfinet.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfinet32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfp.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfpconfg.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfplogvw.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cfpupdat.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Cl.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\claw95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\claw95cf.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\clean.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleaner.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleaner3.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleanIELow.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cleanpc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\click.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmd32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmdagent.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmesys.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmgrdian.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cmon016.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\connectionmonitor.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\control<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpd.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpf9x206.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cpfnt206.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\crashrep.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\csc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssconfg.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssupdat.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cssurf.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ctrl.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cv.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cwnb181.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\cwntdwmo.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\d.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\datemanager.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dcomx.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defalert.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defscangui.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\defwatch.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\deloeminfs.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\deputy.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\divx.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dllcache.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dllreg.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\doors.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dop.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpf.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpfsetup.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dpps2.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\driverctrl.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drwatson.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drweb32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\drwebupw.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dssagent.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dvp95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\dvp95_0.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ecengine.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\efpeadm.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\emsw.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ent.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\esafe.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\escanhnt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\escanv95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\espwatch.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ethereal.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\etrustcipe.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\evpn.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\exantivirus-cnet.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\exe.avxw.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\expert.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\explore.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-agnt95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-prot.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-prot95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\f-stopw.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fact.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fameh32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fast.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fch32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fih32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\findviru.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\firewall.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fixcfg.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fixfp.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fnrb32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fp-win.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fp-win_trial.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fprot.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\frmwrk32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\frw.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsaa.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav530stbyb.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav530wtbyb.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsav95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsgk32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsm32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsma32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\fsmb32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gator.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gav.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbmenu.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbn976rl.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gbpoll.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\generics.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\gmt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guard.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guarddog.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\guardgui.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hacktracersetup.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hbinst.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hbsrv.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\History.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\homeav2010.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hotactio.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hotpatch.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\htlog.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\htpatch.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hwpe.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hxdl.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\hxiul.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamapp.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamserv.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iamstats.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ibmasn.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ibmavsp.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icload95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icloadnt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icmon.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icsupp95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\icsuppnt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Identity.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\idle.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iedll.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iedriver.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\IEShow.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iface.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ifw2000.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\inetlnfo.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\infus.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\infwin.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\init.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\init32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\install[1].exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\install[2].exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\install[3].exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\install[4].exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\install[5].exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\intdel.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\intren.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\iomon98.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\istsvc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jammer.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jdbgmrg.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\jedi.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\JsRcGen.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavlite40eng.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavpers40eng.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kavpf.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kazza.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\keenvalue.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-pf-213-en-win.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-wrl-421-en-win.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\kerio-wrp-421-en-win.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\killprocesssetup161.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldnetmon.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldpro.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldpromenu.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ldscan.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\licmgr.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lnetinfo.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\loader.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\localnet.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lockdown.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lockdown2000.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lookout.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lordpe.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lsetup.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luall.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luau.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\lucomserver.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luinit.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\luspt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MalwareRemoval.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mapisvc32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcagent.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcmnhdlr.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcmscsvc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcnasvc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcproxy.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\McSACore.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcshell.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcshield.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcsysmon.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mctool.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcupdate.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcvsrte.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mcvsshld.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\md.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfin32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfw2en.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mfweng3.02d30.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgavrtcl.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgavrte.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mghtml.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mgui.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\minilog.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mmod.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\monitor.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\moolive.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mostat.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpfagent.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpfservice.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MPFSrv.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mpftray.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mrflux.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mrt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msa.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msapp.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\MSASCui.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msbb.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msblast.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mscache.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msccn32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mscman.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msconfig<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msdm.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msdos.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msiexec16.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mslaugh.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmgt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmsgri32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mssmmc32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mssys.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msvxd.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mu0311ad.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\mwatch.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\n32scanw.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nav.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navap.navapsvc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navapsvc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navapw32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navdx.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navlu32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navnt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navstub.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navw32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\navwnt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nc2000.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ncinst4.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ndd32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\neomonitor.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\neowatchlog.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netarmor.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netd32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netinfo.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netmon.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netscanpro.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netspyhunter-1.2.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\netutils.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nisserv.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nisum.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nmain.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nod32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\normist.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\norton_internet_secu_3.0_407.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\notstart.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npf40_tw_98_nt_me_2k.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npfmessenger.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nprotect.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npscheck.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\npssvc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nsched32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nssys32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nstask32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nsupdate.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntrtscan.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntvdm.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ntxconfig.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nui.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nupgrade.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvarch16.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvc95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nvsvc32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwinst4.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwservice.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\nwtool16.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAcat.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAhlp.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\OAReg.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oasrv.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oaui.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\oaview.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ODSW.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ollydbg.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\onsrvr.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\optimize.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ostronet.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\otfix.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpost.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpostinstall.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\outpostproinstall.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ozn695m5.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\padmin.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\panixk.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\patch.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pav.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavcl.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PavFnSvr.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavproxy.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavprsrv.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavsched.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavsrv51.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pavw.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pccwin98.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcfwallicon.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcip10117_0.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pcscan.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsAuxs.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsGui.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsSvc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pctsTray.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PC_Antispyware2010.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pdfndr.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pdsetup.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PerAvir.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\periscope.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\persfw.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\personalguard<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\personalguard.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\perswf.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pf2.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pfwadmin.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pgmonitr.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pingscan.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\platin.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pop3trap.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\poproxy.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\popscan.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\portdetective.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\portmonitor.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\powerscan.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ppinupdt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pptbc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ppvstop.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prizesurfer.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prmt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\prmvr.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\procdump.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\processmonitor.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\procexplorerv1.0.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\programauditor.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\proport.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\protector.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\protectx.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANCU.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANHost.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSANToManager.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PsCtrls.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PsImSvc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PskSvc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\pspf.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\PSUNMain.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\purge.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qconsole.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qh.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\qserver.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Quick Heal.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\QuickHealCleaner.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rapapp.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav7.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav7win.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rav8win32eng.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ray.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rb32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rcsync.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\realmon.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\reged.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\regedt32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rescue.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rescue32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rrguard.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rscdwld.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rshell.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rtvscan.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rtvscn95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rulaunch.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rwg<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\rwg.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SafetyKeeper.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\safeweb.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sahagent.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Save.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveArmor.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveDefense.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SaveKeep.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\savenow.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sbserv.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scam32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scan32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scan95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scanpm.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\scrscan.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Secure Veteran.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\secureveteran.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\Security Center.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SecurityFighter.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\securitysoldier.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\serv95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setloadorder.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setupvameeval.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\setup_flowprotector_us.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sgssfw32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sh.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shellspyinstall.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shield.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\shn.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\showbehind.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\signcheck.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smart.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smartprotector.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smrtdefp.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sms.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\smss32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\snetcfg.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\soap.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sofi.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\SoftSafeness.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sperm.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spf.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sphinx.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoler.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoolcv.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spoolsv32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spywarexpguard.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\spyxx.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\srexe.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\srng.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ss3edit.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ssgrate.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ssg_4104.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\st2.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\start.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\stcloader.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\supftrl.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\support.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\supporter5.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svchostc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svchosts.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\svshost.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sweep95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sweepnet.sweepsrv.sys.swnetsup.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symlcsvc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symproxysvc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\symtray.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\system.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\system32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\sysupd.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tapinstall.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\taumon.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tbscan.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tca.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tcm.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds-3.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds2-98.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tds2-nt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\teekids.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tfak.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tfak5.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tgbob.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\titanin.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\titaninxp.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\TPSrv.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trickler.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trjscan.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trjsetup.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\trojantrap3.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\TrustWarrior.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tsadbot.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tsc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tvmd.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\tvtmd.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\undoboot.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\updat.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\upgrad.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\utpost.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbcmserv.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbcons.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbust.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbwin9x.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vbwinntw.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vcsetup.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vet32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vet95.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vettray.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vfsetup.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vir-help.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\virusmdpersonalfirewall.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthAux.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthLic.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\VisthUpd.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vnlan300.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vnpc3000.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpc32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpc42.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vpfw30s.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vptray.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vscan40.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vscenu6.02d30.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsched.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsecomr.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vshwin32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsisetup.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsmain.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsmon.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vsstat.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswin9xe.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswinntse.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\vswinperse.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\w32dsm89.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\W3asbas.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\w9x.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\watchdog.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webdav.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\WebProxy.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webscanx.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\webtrap.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wfindv32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\whoswatchingme.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wimmun32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win-bugsfix.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\win32us.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winactive.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winav.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windll32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\window.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windows Police Pro.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\windows.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wininetd.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wininitx.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winlogin.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winmain.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winppr32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winrecon.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winservn.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winssk32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winstart.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winstart001.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wintsk32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\winupdate.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wkufind.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wnad.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wnt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wradmin.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wrctrl.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wsbgate.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxas.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxav.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wscfxfw.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wsctool.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wupdater.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wupdt.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\wyvernworksfirewall.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xpdeluxe.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xpf202en.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\xp_antispyware.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zapro.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zapsetup3001.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zatutor.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zonalm2601.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\zonealarm.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avp32.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avpcc.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\_avpm.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\~1.exe<br />
(SZ)Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\~2.exe<br />
(SZ)Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmatureMaster_1.png"><img class="alignnone size-medium wp-image-2487" title="Adware.Win32.WindowsArmatureMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmatureMaster_1-400x208.png" alt="Adware.Win32.WindowsArmatureMaster" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmatureMaster_2.png"><img class="alignnone size-medium wp-image-2488" title="Adware.Win32.WindowsArmatureMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmatureMaster_2-400x208.png" alt="Adware.Win32.WindowsArmatureMaster" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmatureMaster_3.png"><img class="alignnone size-medium wp-image-2489" title="Adware.Win32.WindowsArmatureMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmatureMaster_3-400x228.png" alt="Adware.Win32.WindowsArmatureMaster" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmatureMaster_4.png"><img class="alignnone size-medium wp-image-2490" title="Adware.Win32.WindowsArmatureMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmatureMaster_4-400x228.png" alt="Adware.Win32.WindowsArmatureMaster" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmatureMaster_5.png"><img class="alignnone size-medium wp-image-2491" title="Adware.Win32.WindowsArmatureMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmatureMaster_5-400x228.png" alt="Adware.Win32.WindowsArmatureMaster" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmatureMaster_6.png"><img class="alignnone size-medium wp-image-2492" title="Adware.Win32.WindowsArmatureMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmatureMaster_6-400x235.png" alt="Adware.Win32.WindowsArmatureMaster" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmatureMaster_7.png"><img class="alignnone size-medium wp-image-2493" title="Adware.Win32.WindowsArmatureMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmatureMaster_7-400x214.png" alt="Adware.Win32.WindowsArmatureMaster" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmatureMaster_8.png"><img class="alignnone size-medium wp-image-2494" title="Adware.Win32.WindowsArmatureMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmatureMaster_8-400x214.png" alt="Adware.Win32.WindowsArmatureMaster" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmatureMaster_9.png"><img class="alignnone size-medium wp-image-2495" title="Adware.Win32.WindowsArmatureMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsArmatureMaster_9-400x211.png" alt="Adware.Win32.WindowsArmatureMaster" width="400" height="211" /></a></strong></p>
<p><strong>How to remove the infection of Windows Armature Master </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsArmatureMaster"><strong>Adware.Win32.WindowsArmatureMaster</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Smart Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/12/26/home-security-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Home Security Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/03/22/cleanup-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">CleanUP Antivirus Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/07/24/windows-armature-master-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Debugging Agent Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/07/24/windows-debugging-agent-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/07/24/windows-debugging-agent-adware-removal-instructions/#comments</comments>
		<pubDate>Sun, 24 Jul 2011 02:09:19 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Debugging Agent]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2475</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Debugging Agent adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsDebuggingAgent. Windows Debugging Agent is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with viruses [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Debugging Agent</strong><strong> </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.WindowsDebuggingAgent" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDebuggingAgent" target="_blank"><strong>Adware.Win32.WindowsDebuggingAgent</strong></a><strong>.</strong></p>
<p><strong>Windows Debugging Agent</strong><strong> </strong><strong></strong>is        a                                          rogue                application.                                                                      A           rogue                           application           tries       to         trick  you   by                                                  displaying                               false                                                positive/misleading               scan                                     results                               report,     which       says                         that   your                                                             computer           has    a            problem,               or         infected          with                                        viruses            or                    trojan,           but         you         will                        not               be          able                  to     fix       it                    before        you                                  purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a title="Adware.Win32.WindowsAccurateProtector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccurateProtector" target="_blank"><strong>Windows Accurate Protector</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsVulnerabilitiesRescuer"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsVulnerabilitiesRescuer"><strong>Windows Vulnerabilities Rescuer</strong></a><strong></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTestMaster"><strong>Windows Test Master</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSalvorTool"><strong>Windows Salvor Tool</strong><strong> </strong><strong> </strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProofnessGuarantor">Windows Proofness Guarantor</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDebuggingCenter"><strong>Windows Debugging Center</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInviolabilitySystem"><strong>Windows Inviolability System</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVComponent"><strong>Windows AV Component</strong><strong> </strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntivirusSystem"><strong>Windows Antivirus System</strong></a><strong> </strong></li>
<li><strong> </strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispyNetwork"><strong>Windows Antispy Network</strong></a><strong> </strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong> Windows Antidanger Center</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong>Windows Accelerating Utility</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWorkChecker" target="_blank"><strong>Windows Work Checker</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMonitoringUtility"><strong> Windows Monitoring Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExaminationUtility"><strong>Windows Examination Utility</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesKiller"><strong>Windows Troubles Killer</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionAlarm"><strong>Windows Protection Alarm</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRescueCenter" target="_blank"><strong>Windows Rescue Center</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrashesDeliverer"><strong>Windows Crashes Deliverer</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSaviourFirewall"><strong>Windows Saviour Firewall</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAvertingSystem"><strong>Windows Averting System</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccidentsPrevention"><strong>Windows Accidents Prevention</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver"><strong>Windows Troubles Solver</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Windows Anticrashes Utility</strong></a></li>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong></strong><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Internet Settings<br />
(DWORD) WarnOnHTTPSToHTTPRedirect = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Internet Settings<br />
(DWORD) WarnOnHTTPSToHTTPRedirect = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingAgent_1.png"><img class="alignnone size-medium wp-image-2476" title="Adware.Win32.WindowsDebuggingAgent" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingAgent_1-400x208.png" alt="Adware.Win32.WindowsDebuggingAgent" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingAgent_2.png"><img class="alignnone size-medium wp-image-2477" title="Adware.Win32.WindowsDebuggingAgent" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingAgent_2-400x208.png" alt="Adware.Win32.WindowsDebuggingAgent" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingAgent_3.png"><img class="alignnone size-medium wp-image-2478" title="Adware.Win32.WindowsDebuggingAgent" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingAgent_3-400x228.png" alt="Adware.Win32.WindowsDebuggingAgent" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingAgent_4.png"><img class="alignnone size-medium wp-image-2479" title="Adware.Win32.WindowsDebuggingAgent" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingAgent_4-400x228.png" alt="Adware.Win32.WindowsDebuggingAgent" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingAgent_5.png"><img class="alignnone size-medium wp-image-2480" title="Adware.Win32.WindowsDebuggingAgent" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingAgent_5-400x235.png" alt="Adware.Win32.WindowsDebuggingAgent" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingAgent_6.png"><img class="alignnone size-medium wp-image-2481" title="Adware.Win32.WindowsDebuggingAgent" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingAgent_6-400x214.png" alt="Adware.Win32.WindowsDebuggingAgent" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingAgent_7.png"><img class="alignnone size-medium wp-image-2482" title="Adware.Win32.WindowsDebuggingAgent" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingAgent_7-400x214.png" alt="Adware.Win32.WindowsDebuggingAgent" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingAgent_8.png"><img class="alignnone size-medium wp-image-2483" title="Adware.Win32.WindowsDebuggingAgent" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingAgent_8-400x211.png" alt="Adware.Win32.WindowsDebuggingAgent" width="400" height="211" /></a></strong></p>
<p><strong>How to remove the infection of Windows Debugging Agent </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDebuggingAgent"><strong>Adware.Win32.WindowsDebuggingAgent</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troublemakers-agent-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troublemakers Agent Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/07/24/windows-debugging-agent-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Accurate Protector Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/07/24/windows-accurate-protector-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/07/24/windows-accurate-protector-adware-removal-instructions/#comments</comments>
		<pubDate>Sun, 24 Jul 2011 01:58:17 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Accurate Protector]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2465</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Accurate Protector adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsAccurateProtector. Windows Accurate Protector is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with viruses [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Accurate Protector</strong><strong> </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.WindowsAccurateProtector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccurateProtector" target="_blank"><strong>Adware.Win32.WindowsAccurateProtector</strong></a><strong>.</strong></p>
<p><strong>Windows Accurate Protector</strong><strong> </strong><strong> </strong>is       a                                          rogue               application.                                                                     A           rogue                           application          tries       to         trick  you   by                                                 displaying                               false                                               positive/misleading              scan                                     results                              report,     which       says                         that   your                                                            computer          has    a            problem,               or         infected         with                                        viruses            or                   trojan,           but         you         will                       not               be          able                  to    fix       it                    before        you                                 purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsVulnerabilitiesRescuer"><strong>Windows Vulnerabilities Rescuer</strong></a><strong></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTestMaster"><strong>Windows Test Master</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSalvorTool"><strong>Windows Salvor Tool</strong><strong> </strong><strong> </strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProofnessGuarantor">Windows Proofness Guarantor</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDebuggingCenter"><strong>Windows Debugging Center</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInviolabilitySystem"><strong>Windows Inviolability System</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVComponent"><strong>Windows AV Component</strong><strong> </strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntivirusSystem"><strong>Windows Antivirus System</strong></a><strong> </strong></li>
<li><strong> </strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispyNetwork"><strong>Windows Antispy Network</strong></a><strong> </strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong> Windows Antidanger Center</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong>Windows Accelerating Utility</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWorkChecker" target="_blank"><strong>Windows Work Checker</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMonitoringUtility"><strong> Windows Monitoring Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExaminationUtility"><strong>Windows Examination Utility</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesKiller"><strong>Windows Troubles Killer</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionAlarm"><strong>Windows Protection Alarm</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRescueCenter" target="_blank"><strong>Windows Rescue Center</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrashesDeliverer"><strong>Windows Crashes Deliverer</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSaviourFirewall"><strong>Windows Saviour Firewall</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAvertingSystem"><strong>Windows Averting System</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccidentsPrevention"><strong>Windows Accidents Prevention</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver"><strong>Windows Troubles Solver</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Windows Anticrashes Utility</strong></a></li>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong></strong><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Internet Settings<br />
(DWORD) WarnOnHTTPSToHTTPRedirect = 0&#215;00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Internet Settings<br />
(DWORD) WarnOnHTTPSToHTTPRedirect = 0&#215;00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAccurateProtector_1.png"><img class="alignnone size-medium wp-image-2466" title="Adware.Win32.WindowsAccurateProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAccurateProtector_1-400x208.png" alt="Adware.Win32.WindowsAccurateProtector" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAccurateProtector_2.png"><img class="alignnone size-medium wp-image-2467" title="Adware.Win32.WindowsAccurateProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAccurateProtector_2-400x208.png" alt="Adware.Win32.WindowsAccurateProtector" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAccurateProtector_3.png"><img class="alignnone size-medium wp-image-2468" title="Adware.Win32.WindowsAccurateProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAccurateProtector_3-400x228.png" alt="Adware.Win32.WindowsAccurateProtector" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAccurateProtector_4.png"><img class="alignnone size-medium wp-image-2469" title="Adware.Win32.WindowsAccurateProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAccurateProtector_4-400x228.png" alt="Adware.Win32.WindowsAccurateProtector" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAccurateProtector_5.png"><img class="alignnone size-medium wp-image-2470" title="Adware.Win32.WindowsAccurateProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAccurateProtector_5-400x235.png" alt="Adware.Win32.WindowsAccurateProtector" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAccurateProtector_6.png"><img class="alignnone size-medium wp-image-2471" title="Adware.Win32.WindowsAccurateProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAccurateProtector_6-400x214.png" alt="Adware.Win32.WindowsAccurateProtector" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAccurateProtector_7.png"><img class="alignnone size-medium wp-image-2472" title="Adware.Win32.WindowsAccurateProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAccurateProtector_7-400x214.png" alt="Adware.Win32.WindowsAccurateProtector" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAccurateProtector_8.png"><img class="alignnone size-medium wp-image-2473" title="Adware.Win32.WindowsAccurateProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAccurateProtector_8-400x211.png" alt="Adware.Win32.WindowsAccurateProtector" width="400" height="211" /></a></strong></p>
<p><strong>How to remove the infection of Windows Accurate Protector </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccurateProtector"><strong>Adware.Win32.WindowsAccurateProtector</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/22/windows-av-software-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows AV Software Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/07/24/windows-accurate-protector-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Shield Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/07/24/security-shield-adware-removal-instructions-2/</link>
		<comments>http://www.anti-malware-blog.com/2011/07/24/security-shield-adware-removal-instructions-2/#comments</comments>
		<pubDate>Sun, 24 Jul 2011 01:48:06 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Security Shield]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2457</guid>
		<description><![CDATA[The Emsisoft malware research team has discoverd a new outbreak of the Security Shield adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.SecurityShield. Security Shield is a rogue application, this is another variant of Security Tool or Security Shield with different color scheme. A rogue application tries to trick you by displaying false positive/misleading scan results [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has  discoverd a new outbreak    of the <strong>Security Shield </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecurityShield" target="_blank">Adware.Win32.SecurityShield.</a></strong></p>
<p><strong>Security Shield </strong>is a rogue application, this is another variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HardDriveDiagnostic" target="_blank"><strong></strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecurityTool" target="_blank"><strong>Security Tool</strong></a> or <strong><a href="http://www.anti-malware-blog.com/2010/12/09/security-shield-adware-removal-instructions/" target="_blank">Security Shield</a></strong> with different color scheme.                 A  rogue   application  tries to trick you by displaying         false           positive/misleading   scan results  report,  which   says     that  your           computer has a problem, or  infected with      viruses    or   trojan,   but  you   will not be able       to fix it    before you       purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%UserProfile%\Local Settings\Application Data\%random%.exe</li>
<li>%UserProfile%\Start Menu\Programs\Security Shield.lnk</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.SecurityShield_1.png"><img class="alignnone size-full wp-image-2458" title="Adware.Win32.SecurityShield" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.SecurityShield_1.png" alt="Adware.Win32.SecurityShield" width="299" height="126" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.SecurityShield_2.png"><img class="alignnone size-medium wp-image-2459" title="Adware.Win32.SecurityShield" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.SecurityShield_2-400x318.png" alt="Adware.Win32.SecurityShield" width="400" height="318" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.SecurityShield_3.png"><img class="alignnone size-medium wp-image-2460" title="Adware.Win32.SecurityShield" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.SecurityShield_3-400x366.png" alt="Adware.Win32.SecurityShield" width="400" height="366" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.SecurityShield_4.png"><img class="alignnone size-medium wp-image-2461" title="Adware.Win32.SecurityShield" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.SecurityShield_4-400x331.png" alt="Adware.Win32.SecurityShield" width="400" height="331" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.SecurityShield_5.png"><img class="alignnone size-medium wp-image-2462" title="Adware.Win32.SecurityShield" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.SecurityShield_5-400x247.png" alt="Adware.Win32.SecurityShield" width="400" height="247" /></a></strong></p>
<p><strong>How to remove the infection of Security Shield</strong><strong></strong><strong> </strong><strong>(<a title="Adware.Win32.SecurityShield" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecurityShield" target="_blank">Adware.Win32.</a></strong><a title="Adware.Win32.SecurityShield" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecurityShield" target="_blank"><strong>SecurityShield</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/12/09/security-shield-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Shield Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/19/security-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/06/11/personal-shield-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Personal Shield Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/09/05/opencloud-security-adware-removal-instructions/" rel="bookmark" class="crp_title">OpenCloud Security Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/11/pc-security-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">PC Security 2011 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/07/24/security-shield-adware-removal-instructions-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Vulnerabilities Rescuer Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/07/09/windows-vulnerabilities-rescuer-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/07/09/windows-vulnerabilities-rescuer-adware-removal-instructions/#comments</comments>
		<pubDate>Sat, 09 Jul 2011 08:46:58 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Vulnerabilities Rescuer]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2446</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Vulnerabilities Rescuer adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsVulnerabilitiesRescuer. Windows Vulnerabilities Rescuer is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with viruses [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Vulnerabilities Rescuer</strong><strong> </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsVulnerabilitiesRescuer"><strong>Adware.Win32.WindowsVulnerabilitiesRescuer</strong></a><strong>.</strong></p>
<p><strong>Windows Vulnerabilities Rescuer</strong><strong> </strong><strong> </strong>is      a                                          rogue              application.                                                                    A           rogue                           application         tries       to         trick  you   by                                                displaying                               false                                              positive/misleading              scan                                    results                             report,     which       says                         that   your                                                           computer          has   a            problem,               or         infected         with                                       viruses            or                  trojan,           but         you         will                      not               be          able                  to    fix       it                   before        you                                purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTestMaster"><strong>Windows Test Master</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSalvorTool"><strong>Windows Salvor Tool</strong><strong> </strong><strong> </strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProofnessGuarantor">Windows Proofness Guarantor</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDebuggingCenter"><strong>Windows Debugging Center</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInviolabilitySystem"><strong>Windows Inviolability System</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVComponent"><strong>Windows AV Component</strong><strong> </strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntivirusSystem"><strong>Windows Antivirus System</strong></a><strong> </strong></li>
<li><strong> </strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispyNetwork"><strong>Windows Antispy Network</strong></a><strong> </strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong> Windows Antidanger Center</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong>Windows Accelerating Utility</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWorkChecker" target="_blank"><strong>Windows Work Checker</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMonitoringUtility"><strong> Windows Monitoring Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExaminationUtility"><strong>Windows Examination Utility</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesKiller"><strong>Windows Troubles Killer</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionAlarm"><strong>Windows Protection Alarm</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRescueCenter" target="_blank"><strong>Windows Rescue Center</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrashesDeliverer"><strong>Windows Crashes Deliverer</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSaviourFirewall"><strong>Windows Saviour Firewall</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAvertingSystem"><strong>Windows Averting System</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccidentsPrevention"><strong>Windows Accidents Prevention</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver"><strong>Windows Troubles Solver</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Windows Anticrashes Utility</strong></a></li>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong></strong><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsVulnerabilitiesRescuer_1.png"><img class="alignnone size-medium wp-image-2447" title="Adware.Win32.WindowsVulnerabilitiesRescuer" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsVulnerabilitiesRescuer_1-400x208.png" alt="Adware.Win32.WindowsVulnerabilitiesRescuer" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsVulnerabilitiesRescuer_2.png"><img class="alignnone size-medium wp-image-2448" title="Adware.Win32.WindowsVulnerabilitiesRescuer" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsVulnerabilitiesRescuer_2-400x208.png" alt="Adware.Win32.WindowsVulnerabilitiesRescuer" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsVulnerabilitiesRescuer_3.png"><img class="alignnone size-medium wp-image-2449" title="Adware.Win32.WindowsVulnerabilitiesRescuer" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsVulnerabilitiesRescuer_3-400x228.png" alt="Adware.Win32.WindowsVulnerabilitiesRescuer" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsVulnerabilitiesRescuer_4.png"><img class="alignnone size-medium wp-image-2450" title="Adware.Win32.WindowsVulnerabilitiesRescuer" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsVulnerabilitiesRescuer_4-400x228.png" alt="Adware.Win32.WindowsVulnerabilitiesRescuer" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsVulnerabilitiesRescuer_5.png"><img class="alignnone size-medium wp-image-2451" title="Adware.Win32.WindowsVulnerabilitiesRescuer" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsVulnerabilitiesRescuer_5-400x235.png" alt="Adware.Win32.WindowsVulnerabilitiesRescuer" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsVulnerabilitiesRescuer_6.png"><img class="alignnone size-medium wp-image-2452" title="Adware.Win32.WindowsVulnerabilitiesRescuer" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsVulnerabilitiesRescuer_6-400x214.png" alt="Adware.Win32.WindowsVulnerabilitiesRescuer" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsVulnerabilitiesRescuer_7.png"><img class="alignnone size-medium wp-image-2453" title="Adware.Win32.WindowsVulnerabilitiesRescuer" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsVulnerabilitiesRescuer_7-400x214.png" alt="Adware.Win32.WindowsVulnerabilitiesRescuer" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsVulnerabilitiesRescuer_8.png"><img class="alignnone size-medium wp-image-2454" title="Adware.Win32.WindowsVulnerabilitiesRescuer" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsVulnerabilitiesRescuer_8-400x209.png" alt="Adware.Win32.WindowsVulnerabilitiesRescuer" width="400" height="209" /></a></strong></p>
<p><strong>How to remove the infection of Windows Vulnerabilities Rescuer </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsVulnerabilitiesRescuer"><strong>Adware.Win32.WindowsVulnerabilitiesRescuer</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/22/windows-av-software-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows AV Software Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/07/09/windows-vulnerabilities-rescuer-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Test Master Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/07/09/windows-test-master-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/07/09/windows-test-master-adware-removal-instructions/#comments</comments>
		<pubDate>Sat, 09 Jul 2011 08:36:44 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Test Master]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2435</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Test Master adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsTestMaster. Windows Test Master is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Test Master </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTestMaster"><strong>Adware.Win32.WindowsTestMaster</strong></a><strong>.</strong></p>
<p><strong>Windows Test Master</strong><strong> </strong><strong> </strong>is     a                                          rogue             application.                                                                   A           rogue                           application        tries       to         trick  you   by                                               displaying                               false                                             positive/misleading              scan                                   results                            report,     which       says                         that   your                                                          computer          has  a            problem,               or         infected         with                                      viruses            or                 trojan,           but         you         will                      not              be          able                  to    fix       it                  before        you                                purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSalvorTool"><strong>Windows Salvor Tool</strong><strong> </strong><strong> </strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProofnessGuarantor">Windows Proofness Guarantor</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDebuggingCenter"><strong>Windows Debugging Center</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInviolabilitySystem"><strong>Windows Inviolability System</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVComponent"><strong>Windows AV Component</strong><strong> </strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntivirusSystem"><strong>Windows Antivirus System</strong></a><strong> </strong></li>
<li><strong> </strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispyNetwork"><strong>Windows Antispy Network</strong></a><strong> </strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong> Windows Antidanger Center</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong>Windows Accelerating Utility</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWorkChecker" target="_blank"><strong>Windows Work Checker</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMonitoringUtility"><strong> Windows Monitoring Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExaminationUtility"><strong>Windows Examination Utility</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesKiller"><strong>Windows Troubles Killer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionAlarm"><strong>Windows Protection Alarm</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRescueCenter" target="_blank"><strong>Windows Rescue Center</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrashesDeliverer"><strong>Windows Crashes Deliverer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSaviourFirewall"><strong>Windows Saviour Firewall</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAvertingSystem"><strong>Windows Averting System</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccidentsPrevention"><strong>Windows Accidents Prevention</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver"><strong>Windows Troubles Solver</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Windows Anticrashes Utility</strong></a></li>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong></strong><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsTestMaster_1.png"><img class="alignnone size-medium wp-image-2436" title="Adware.Win32.WindowsTestMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsTestMaster_1-400x208.png" alt="Adware.Win32.WindowsTestMaster" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsTestMaster_2.png"><img class="alignnone size-medium wp-image-2437" title="Adware.Win32.WindowsTestMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsTestMaster_2-400x208.png" alt="Adware.Win32.WindowsTestMaster" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsTestMaster_3.png"><img class="alignnone size-medium wp-image-2438" title="Adware.Win32.WindowsTestMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsTestMaster_3-400x228.png" alt="Adware.Win32.WindowsTestMaster" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsTestMaster_4.png"><img class="alignnone size-medium wp-image-2439" title="Adware.Win32.WindowsTestMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsTestMaster_4-400x228.png" alt="Adware.Win32.WindowsTestMaster" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsTestMaster_5.png"><img class="alignnone size-medium wp-image-2440" title="Adware.Win32.WindowsTestMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsTestMaster_5-400x235.png" alt="Adware.Win32.WindowsTestMaster" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsTestMaster_6.png"><img class="alignnone size-medium wp-image-2441" title="Adware.Win32.WindowsTestMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsTestMaster_6-400x214.png" alt="Adware.Win32.WindowsTestMaster" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsTestMaster_7.png"><img class="alignnone size-medium wp-image-2442" title="Adware.Win32.WindowsTestMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsTestMaster_7-400x209.png" alt="Adware.Win32.WindowsTestMaster" width="400" height="209" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsTestMaster_8.png"><img class="alignnone size-medium wp-image-2443" title="Adware.Win32.WindowsTestMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsTestMaster_8-400x325.png" alt="Adware.Win32.WindowsTestMaster" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows Test Master </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTestMaster"><strong>Adware.Win32.WindowsTestMaster</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/22/windows-av-software-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows AV Software Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/07/09/windows-test-master-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Salvor Tool Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/07/09/windows-salvor-tool-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/07/09/windows-salvor-tool-adware-removal-instructions/#comments</comments>
		<pubDate>Sat, 09 Jul 2011 08:28:54 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Salvor Tool]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2423</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Salvor Tool adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsSalvorTool. Windows Salvor Tool is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Salvor Tool </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSalvorTool"><strong>Adware.Win32.WindowsSalvorTool</strong></a><strong>.</strong></p>
<p><strong>Windows Salvor Tool</strong><strong> </strong><strong> </strong>is    a                                          rogue            application.                                                                  A           rogue                           application       tries       to         trick  you   by                                              displaying                               false                                            positive/misleading              scan                                  results                            report,    which       says                         that   your                                                         computer          has  a           problem,               or         infected         with                                     viruses            or                 trojan,          but         you         will                      not             be          able                  to    fix       it                 before        you                                purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProofnessGuarantor">Windows Proofness Guarantor</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDebuggingCenter"><strong>Windows Debugging Center</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInviolabilitySystem"><strong>Windows Inviolability System</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVComponent"><strong>Windows AV Component</strong><strong> </strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntivirusSystem"><strong>Windows Antivirus System</strong></a><strong> </strong></li>
<li><strong> </strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispyNetwork"><strong>Windows Antispy Network</strong></a><strong></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong> Windows Antidanger Center</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong>Windows Accelerating Utility</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWorkChecker" target="_blank"><strong>Windows Work Checker</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMonitoringUtility"><strong> Windows Monitoring Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExaminationUtility"><strong>Windows Examination Utility</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesKiller"><strong>Windows Troubles Killer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionAlarm"><strong>Windows Protection Alarm</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRescueCenter" target="_blank"><strong>Windows Rescue Center</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrashesDeliverer"><strong>Windows Crashes Deliverer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSaviourFirewall"><strong>Windows Saviour Firewall</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAvertingSystem"><strong>Windows Averting System</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccidentsPrevention"><strong>Windows Accidents Prevention</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver"><strong>Windows Troubles Solver</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Windows Anticrashes Utility</strong></a></li>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong></strong><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsSalvorTool_1.png"><img class="alignnone size-medium wp-image-2424" title="Adware.Win32.WindowsSalvorTool" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsSalvorTool_1-400x208.png" alt="Adware.Win32.WindowsSalvorTool" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsSalvorTool_2.png"><img class="alignnone size-medium wp-image-2425" title="Adware.Win32.WindowsSalvorTool" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsSalvorTool_2-400x208.png" alt="Adware.Win32.WindowsSalvorTool" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsSalvorTool_3.png"><img class="alignnone size-medium wp-image-2426" title="Adware.Win32.WindowsSalvorTool" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsSalvorTool_3-400x228.png" alt="Adware.Win32.WindowsSalvorTool" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsSalvorTool_4.png"><img class="alignnone size-medium wp-image-2427" title="Adware.Win32.WindowsSalvorTool" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsSalvorTool_4-400x228.png" alt="Adware.Win32.WindowsSalvorTool" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsSalvorTool_5.png"><img class="alignnone size-medium wp-image-2428" title="Adware.Win32.WindowsSalvorTool" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsSalvorTool_5-400x235.png" alt="Adware.Win32.WindowsSalvorTool" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsSalvorTool_6.png"><img class="alignnone size-medium wp-image-2429" title="Adware.Win32.WindowsSalvorTool" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsSalvorTool_6-400x214.png" alt="Adware.Win32.WindowsSalvorTool" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsSalvorTool_7.png"><img class="alignnone size-medium wp-image-2430" title="Adware.Win32.WindowsSalvorTool" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsSalvorTool_7-400x214.png" alt="Adware.Win32.WindowsSalvorTool" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsSalvorTool_8.png"><img class="alignnone size-medium wp-image-2431" title="Adware.Win32.WindowsSalvorTool" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsSalvorTool_8-400x209.png" alt="Adware.Win32.WindowsSalvorTool" width="400" height="209" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsSalvorTool_9.png"><img class="alignnone size-medium wp-image-2432" title="Adware.Win32.WindowsSalvorTool" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsSalvorTool_9-400x325.png" alt="Adware.Win32.WindowsSalvorTool" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows Salvor Tool </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSalvorTool"><strong>Adware.Win32.WindowsSalvorTool</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<p><strong><br />
</strong></p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/22/windows-av-software-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows AV Software Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/25/windows-optimal-tool-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Optimal Tool Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/07/09/windows-salvor-tool-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Proofness Guarantor Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/07/08/windows-proofness-guarantor-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/07/08/windows-proofness-guarantor-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 08 Jul 2011 19:31:13 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Proofness Guarantor]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2411</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Proofness Guarantor adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsProofnessGuarantor. Windows Proofness Guarantor is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Proofness Guarantor </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProofnessGuarantor"><strong>Adware.Win32.</strong><strong>WindowsProofnessGuarantor</strong></a><strong>.</strong></p>
<p><strong>Windows Proofness Guarantor</strong><strong> </strong><strong></strong>is   a                                          rogue           application.                                                                 A           rogue                           application       tries      to         trick  you   by                                             displaying                               false                                           positive/misleading              scan                                 results                            report,    which      says                         that   your                                                        computer          has  a           problem,              or         infected         with                                    viruses            or                 trojan,          but        you         will                      not             be         able                  to    fix       it                 before       you                                purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDebuggingCenter"><strong>Windows Debugging Center</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInviolabilitySystem"><strong>Windows Inviolability System</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVComponent"><strong>Windows AV Component</strong><strong> </strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntivirusSystem"><strong>Windows Antivirus System</strong></a><strong></strong></li>
<li><strong></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispyNetwork"><strong>Windows Antispy Network</strong></a><strong></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong> Windows Antidanger Center</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong>Windows Accelerating Utility</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWorkChecker" target="_blank"><strong>Windows Work Checker</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMonitoringUtility"><strong> Windows Monitoring Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExaminationUtility"><strong>Windows Examination Utility</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesKiller"><strong>Windows Troubles Killer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionAlarm"><strong>Windows Protection Alarm</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRescueCenter" target="_blank"><strong>Windows Rescue Center</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrashesDeliverer"><strong>Windows Crashes Deliverer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSaviourFirewall"><strong>Windows Saviour Firewall</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAvertingSystem"><strong>Windows Averting System</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccidentsPrevention"><strong>Windows Accidents Prevention</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver"><strong>Windows Troubles Solver</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Windows Anticrashes Utility</strong></a></li>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong></strong><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsProofnessGuarantor_1.png"><img class="alignnone size-medium wp-image-2412" title="Adware.Win32.WindowsProofnessGuarantor" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsProofnessGuarantor_1-400x208.png" alt="Adware.Win32.WindowsProofnessGuarantor" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsProofnessGuarantor_2.png"><img class="alignnone size-medium wp-image-2413" title="Adware.Win32.WindowsProofnessGuarantor" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsProofnessGuarantor_2-400x208.png" alt="Adware.Win32.WindowsProofnessGuarantor" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsProofnessGuarantor_3.png"><img class="alignnone size-medium wp-image-2414" title="Adware.Win32.WindowsProofnessGuarantor" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsProofnessGuarantor_3-400x228.png" alt="Adware.Win32.WindowsProofnessGuarantor" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsProofnessGuarantor_4.png"><img class="alignnone size-medium wp-image-2415" title="Adware.Win32.WindowsProofnessGuarantor" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsProofnessGuarantor_4-400x228.png" alt="Adware.Win32.WindowsProofnessGuarantor" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsProofnessGuarantor_5.png"><img class="alignnone size-medium wp-image-2416" title="Adware.Win32.WindowsProofnessGuarantor" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsProofnessGuarantor_5-400x235.png" alt="Adware.Win32.WindowsProofnessGuarantor" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsProofnessGuarantor_6.png"><img class="alignnone size-medium wp-image-2417" title="Adware.Win32.WindowsProofnessGuarantor" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsProofnessGuarantor_6-400x214.png" alt="Adware.Win32.WindowsProofnessGuarantor" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsProofnessGuarantor_7.png"><img class="alignnone size-medium wp-image-2418" title="Adware.Win32.WindowsProofnessGuarantor" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsProofnessGuarantor_7-400x214.png" alt="Adware.Win32.WindowsProofnessGuarantor" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsProofnessGuarantor_8.png"><img class="alignnone size-medium wp-image-2419" title="Adware.Win32.WindowsProofnessGuarantor" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsProofnessGuarantor_8-400x209.png" alt="Adware.Win32.WindowsProofnessGuarantor" width="400" height="209" /></a></strong></p>
<p><strong>How to remove the infection of Windows Proofness Guarantor </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProofnessGuarantor"><strong>Adware.Win32.</strong><strong>WindowsProofnessGuarantor</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/22/windows-av-software-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows AV Software Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/07/08/windows-proofness-guarantor-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Debugging Center Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/07/08/windows-debugging-center-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/07/08/windows-debugging-center-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 08 Jul 2011 19:20:24 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Debugging Center]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2400</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Debugging Center adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsDebuggingCenter. Windows Debugging Center is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Debugging Center </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDebuggingCenter"><strong>Adware.Win32.WindowsDebuggingCenter</strong></a><strong>.</strong></p>
<p><strong>Windows Debugging Center </strong><strong></strong>is   a                                         rogue           application.                                                                A          rogue                           application       tries      to        trick  you   by                                             displaying                              false                                          positive/misleading              scan                                results                            report,    which      says                        that   your                                                       computer          has  a           problem,              or        infected         with                                    viruses           or                 trojan,          but        you         will                     not             be         able                  to   fix       it                 before       you                               purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInviolabilitySystem"><strong>Windows Inviolability System</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVComponent"><strong>Windows AV Component</strong><strong> </strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntivirusSystem"><strong>Windows Antivirus System</strong></a><strong></strong></li>
<li><strong></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispyNetwork"><strong>Windows Antispy Network</strong></a><strong></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong> Windows Antidanger Center</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong>Windows Accelerating Utility</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWorkChecker" target="_blank"><strong>Windows Work Checker</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMonitoringUtility"><strong> Windows Monitoring Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExaminationUtility"><strong>Windows Examination Utility</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesKiller"><strong>Windows Troubles Killer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionAlarm"><strong>Windows Protection Alarm</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRescueCenter" target="_blank"><strong>Windows Rescue Center</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrashesDeliverer"><strong>Windows Crashes Deliverer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSaviourFirewall"><strong>Windows Saviour Firewall</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAvertingSystem"><strong>Windows Averting System</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccidentsPrevention"><strong>Windows Accidents Prevention</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver"><strong>Windows Troubles Solver</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Windows Anticrashes Utility</strong></a></li>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong></strong><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingCenter_1.png"><img class="alignnone size-medium wp-image-2401" title="Adware.Win32.WindowsDebuggingCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingCenter_1-400x208.png" alt="Adware.Win32.WindowsDebuggingCenter" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingCenter_2.png"><img class="alignnone size-medium wp-image-2402" title="Adware.Win32.WindowsDebuggingCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingCenter_2-400x208.png" alt="Adware.Win32.WindowsDebuggingCenter" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingCenter_3.png"><img class="alignnone size-medium wp-image-2403" title="Adware.Win32.WindowsDebuggingCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingCenter_3-400x228.png" alt="Adware.Win32.WindowsDebuggingCenter" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingCenter_4.png"><img class="alignnone size-medium wp-image-2404" title="Adware.Win32.WindowsDebuggingCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingCenter_4-400x228.png" alt="Adware.Win32.WindowsDebuggingCenter" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingCenter_5.png"><img class="alignnone size-medium wp-image-2405" title="Adware.Win32.WindowsDebuggingCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingCenter_5-400x228.png" alt="Adware.Win32.WindowsDebuggingCenter" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingCenter_6.png"><img class="alignnone size-medium wp-image-2406" title="Adware.Win32.WindowsDebuggingCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingCenter_6-400x235.png" alt="Adware.Win32.WindowsDebuggingCenter" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingCenter_7.png"><img class="alignnone size-medium wp-image-2407" title="Adware.Win32.WindowsDebuggingCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingCenter_7-400x214.png" alt="Adware.Win32.WindowsDebuggingCenter" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingCenter_8.png"><img class="alignnone size-medium wp-image-2408" title="Adware.Win32.WindowsDebuggingCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingCenter_8-400x214.png" alt="Adware.Win32.WindowsDebuggingCenter" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingCenter_9.png"><img class="alignnone size-medium wp-image-2409" title="Adware.Win32.WindowsDebuggingCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsDebuggingCenter_9-400x209.png" alt="Adware.Win32.WindowsDebuggingCenter" width="400" height="209" /></a></strong></p>
<p><strong>How to remove the infection of Windows Debugging Center </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDebuggingCenter"><strong>Adware.Win32.WindowsDebuggingCenter</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/22/windows-av-software-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows AV Software Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/07/08/windows-debugging-center-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Inviolability System Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/07/05/windows-inviolability-system-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/07/05/windows-inviolability-system-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 05 Jul 2011 09:52:24 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Inviolability System]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2388</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Inviolability System adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsInviolabilitySystem. Windows Inviolability System is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Inviolability System </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInviolabilitySystem"><strong>Adware.Win32.WindowsInviolabilitySystem</strong></a><strong>.</strong></p>
<p><strong>Windows Inviolability System </strong><strong></strong>is   a                                        rogue           application.                                                               A         rogue                           application       tries      to       trick  you   by                                             displaying                             false                                         positive/misleading              scan                               results                            report,    which      says                       that   your                                                      computer          has  a           problem,              or       infected         with                                    viruses          or                 trojan,          but        you         will                    not             be         able                  to   fix      it                 before       you                              purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVComponent"><strong>Windows AV Component</strong><strong></strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntivirusSystem"><strong>Windows Antivirus System</strong></a><strong></strong></li>
<li><strong></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispyNetwork"><strong>Windows Antispy Network</strong></a><strong></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong> Windows Antidanger Center</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong>Windows Accelerating Utility</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWorkChecker" target="_blank"><strong>Windows Work Checker</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMonitoringUtility"><strong> Windows Monitoring Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExaminationUtility"><strong>Windows Examination Utility</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesKiller"><strong>Windows Troubles Killer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionAlarm"><strong>Windows Protection Alarm</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRescueCenter" target="_blank"><strong>Windows Rescue Center</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrashesDeliverer"><strong>Windows Crashes Deliverer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSaviourFirewall"><strong>Windows Saviour Firewall</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAvertingSystem"><strong>Windows Averting System</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccidentsPrevention"><strong>Windows Accidents Prevention</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver"><strong>Windows Troubles Solver</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Windows Anticrashes Utility</strong></a></li>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong></strong><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsInviolabilitySystem_1.png"><img class="alignnone size-medium wp-image-2389" title="Adware.Win32.WindowsInviolabilitySystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsInviolabilitySystem_1-400x208.png" alt="Adware.Win32.WindowsInviolabilitySystem" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsInviolabilitySystem_2.png"><img class="alignnone size-medium wp-image-2390" title="Adware.Win32.WindowsInviolabilitySystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsInviolabilitySystem_2-400x208.png" alt="Adware.Win32.WindowsInviolabilitySystem" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsInviolabilitySystem_3.png"><img class="alignnone size-medium wp-image-2391" title="Adware.Win32.WindowsInviolabilitySystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsInviolabilitySystem_3-400x228.png" alt="Adware.Win32.WindowsInviolabilitySystem" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsInviolabilitySystem_4.png"><img class="alignnone size-medium wp-image-2392" title="Adware.Win32.WindowsInviolabilitySystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsInviolabilitySystem_4-400x228.png" alt="Adware.Win32.WindowsInviolabilitySystem" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsInviolabilitySystem_5.png"><img class="alignnone size-medium wp-image-2393" title="Adware.Win32.WindowsInviolabilitySystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsInviolabilitySystem_5-400x235.png" alt="Adware.Win32.WindowsInviolabilitySystem" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsInviolabilitySystem_6.png"><img class="alignnone size-medium wp-image-2394" title="Adware.Win32.WindowsInviolabilitySystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsInviolabilitySystem_6-400x214.png" alt="Adware.Win32.WindowsInviolabilitySystem" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsInviolabilitySystem_7.png"><img class="alignnone size-medium wp-image-2395" title="Adware.Win32.WindowsInviolabilitySystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsInviolabilitySystem_7-400x214.png" alt="Adware.Win32.WindowsInviolabilitySystem" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsInviolabilitySystem_8.png"><img class="alignnone size-medium wp-image-2396" title="Adware.Win32.WindowsInviolabilitySystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsInviolabilitySystem_8-400x211.png" alt="Adware.Win32.WindowsInviolabilitySystem" width="400" height="211" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsInviolabilitySystem_9.png"><img class="alignnone size-medium wp-image-2397" title="Adware.Win32.WindowsInviolabilitySystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsInviolabilitySystem_9-400x325.png" alt="Adware.Win32.WindowsInviolabilitySystem" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows Inviolability System </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInviolabilitySystem"><strong>Adware.Win32.WindowsInviolabilitySystem</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/19/windows-emergency-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Emergency System Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/07/05/windows-inviolability-system-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows AV Component Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/07/05/windows-av-component-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/07/05/windows-av-component-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 05 Jul 2011 09:45:16 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows AV Component]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2377</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows AV Component adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsAVComponent. Windows AV Component is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows AV Component </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVComponent"><strong>Adware.Win32.WindowsAVComponent</strong></a><strong>.</strong></p>
<p><strong>Windows AV Component</strong><strong> </strong>is   a                                       rogue           application.                                                              A         rogue                          application       tries      to       trick  you   by                                            displaying                            false                                        positive/misleading              scan                              results                            report,    which      says                      that   your                                                     computer          has  a           problem,              or      infected         with                                    viruses         or                 trojan,          but        you         will                   not             be         able                  to   fix     it                 before       you                             purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntivirusSystem"><strong>Windows Antivirus System</strong></a><strong></strong></li>
<li><strong></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispyNetwork"><strong>Windows Antispy Network</strong></a><strong></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong> Windows Antidanger Center</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong>Windows Accelerating Utility</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWorkChecker" target="_blank"><strong>Windows Work Checker</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMonitoringUtility"><strong> Windows Monitoring Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExaminationUtility"><strong>Windows Examination Utility</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesKiller"><strong>Windows Troubles Killer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionAlarm"><strong>Windows Protection Alarm</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRescueCenter" target="_blank"><strong>Windows Rescue Center</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrashesDeliverer"><strong>Windows Crashes Deliverer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSaviourFirewall"><strong>Windows Saviour Firewall</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAvertingSystem"><strong>Windows Averting System</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccidentsPrevention"><strong>Windows Accidents Prevention</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver"><strong>Windows Troubles Solver</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Windows Anticrashes Utility</strong></a></li>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong></strong><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAVComponent_1.png"><img class="alignnone size-medium wp-image-2378" title="Adware.Win32.WindowsAVComponent" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAVComponent_1-400x208.png" alt="Adware.Win32.WindowsAVComponent" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAVComponent_2.png"><img class="alignnone size-medium wp-image-2379" title="Adware.Win32.WindowsAVComponent" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAVComponent_2-400x208.png" alt="Adware.Win32.WindowsAVComponent" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAVComponent_3.png"><img class="alignnone size-medium wp-image-2380" title="Adware.Win32.WindowsAVComponent" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAVComponent_3-400x228.png" alt="Adware.Win32.WindowsAVComponent" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAVComponent_4.png"><img class="alignnone size-medium wp-image-2381" title="Adware.Win32.WindowsAVComponent" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAVComponent_4-400x228.png" alt="Adware.Win32.WindowsAVComponent" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAVComponent_5.png"><img class="alignnone size-medium wp-image-2382" title="Adware.Win32.WindowsAVComponent" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAVComponent_5-400x235.png" alt="Adware.Win32.WindowsAVComponent" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAVComponent_6.png"><img class="alignnone size-medium wp-image-2383" title="Adware.Win32.WindowsAVComponent" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAVComponent_6-400x214.png" alt="Adware.Win32.WindowsAVComponent" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAVComponent_7.png"><img class="alignnone size-medium wp-image-2384" title="Adware.Win32.WindowsAVComponent" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAVComponent_7-400x214.png" alt="Adware.Win32.WindowsAVComponent" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAVComponent_8.png"><img class="alignnone size-medium wp-image-2385" title="Adware.Win32.WindowsAVComponent" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAVComponent_8-400x211.png" alt="Adware.Win32.WindowsAVComponent" width="400" height="211" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAVComponent_9.png"><img class="alignnone size-medium wp-image-2386" title="Adware.Win32.WindowsAVComponent" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAVComponent_9-400x325.png" alt="Adware.Win32.WindowsAVComponent" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows AV Component </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVComponent"><strong>Adware.Win32.WindowsAVComponent</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/22/windows-av-software-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows AV Software Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/07/05/windows-av-component-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Antivirus System Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/07/05/windows-antivirus-system-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/07/05/windows-antivirus-system-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 05 Jul 2011 09:36:23 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Antivirus System]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2365</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Antivirus System adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsAntivirusSystem. Windows Antivirus System is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Antivirus System </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntivirusSystem"><strong>Adware.Win32.WindowsAntivirusSystem</strong></a><strong>.</strong></p>
<p><strong> Windows Antivirus System </strong>is   a                                      rogue           application.                                                             A         rogue                         application       tries      to       trick  you   by                                           displaying                            false                                       positive/misleading             scan                              results                           report,    which      says                      that   your                                                    computer          has  a          problem,              or      infected         with                                   viruses         or                 trojan,          but       you         will                   not             be         able                 to   fix     it                 before       you                            purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispyNetwork"><strong>Windows Antispy Network</strong></a><strong></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong> Windows Antidanger Center</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong>Windows Accelerating Utility</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWorkChecker" target="_blank"><strong>Windows Work Checker</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMonitoringUtility"><strong> Windows Monitoring Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExaminationUtility"><strong>Windows Examination Utility</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesKiller"><strong>Windows Troubles Killer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionAlarm"><strong>Windows Protection Alarm</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRescueCenter" target="_blank"><strong>Windows Rescue Center</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrashesDeliverer"><strong>Windows Crashes Deliverer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSaviourFirewall"><strong>Windows Saviour Firewall</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAvertingSystem"><strong>Windows Averting System</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccidentsPrevention"><strong>Windows Accidents Prevention</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver"><strong>Windows Troubles Solver</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Windows Anticrashes Utility</strong></a></li>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong></strong><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntivirusSystem_1.png"><img class="alignnone size-medium wp-image-2366" title="Adware.Win32.WindowsAntivirusSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntivirusSystem_1-400x208.png" alt="Adware.Win32.WindowsAntivirusSystem" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntivirusSystem_2.png"><img class="alignnone size-medium wp-image-2367" title="Adware.Win32.WindowsAntivirusSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntivirusSystem_2-400x208.png" alt="Adware.Win32.WindowsAntivirusSystem" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntivirusSystem_3.png"><img class="alignnone size-medium wp-image-2368" title="Adware.Win32.WindowsAntivirusSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntivirusSystem_3-400x228.png" alt="Adware.Win32.WindowsAntivirusSystem" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntivirusSystem_4.png"><img class="alignnone size-medium wp-image-2369" title="Adware.Win32.WindowsAntivirusSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntivirusSystem_4-400x228.png" alt="Adware.Win32.WindowsAntivirusSystem" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntivirusSystem_5.png"><img class="alignnone size-medium wp-image-2370" title="Adware.Win32.WindowsAntivirusSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntivirusSystem_5-400x235.png" alt="Adware.Win32.WindowsAntivirusSystem" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntivirusSystem_6.png"><img class="alignnone size-medium wp-image-2371" title="Adware.Win32.WindowsAntivirusSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntivirusSystem_6-400x214.png" alt="Adware.Win32.WindowsAntivirusSystem" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntivirusSystem_7.png"><img class="alignnone size-medium wp-image-2372" title="Adware.Win32.WindowsAntivirusSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntivirusSystem_7-400x214.png" alt="Adware.Win32.WindowsAntivirusSystem" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntivirusSystem_8.png"><img class="alignnone size-medium wp-image-2373" title="Adware.Win32.WindowsAntivirusSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntivirusSystem_8-400x211.png" alt="Adware.Win32.WindowsAntivirusSystem" width="400" height="211" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntivirusSystem_9.png"><img class="alignnone size-medium wp-image-2374" title="Adware.Win32.WindowsAntivirusSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntivirusSystem_9-400x325.png" alt="Adware.Win32.WindowsAntivirusSystem" width="400" height="325" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntivirusSystem_10.png"><img class="alignnone size-medium wp-image-2375" title="Adware.Win32.WindowsAntivirusSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntivirusSystem_10-400x325.png" alt="Adware.Win32.WindowsAntivirusSystem" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows Antivirus System</strong><strong> </strong><strong> </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntivirusSystem"><strong>Adware.Win32.WindowsAntivirusSystem</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/22/windows-av-software-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows AV Software Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/07/05/windows-antivirus-system-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Antispy Network Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/07/05/windows-antispy-network-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/07/05/windows-antispy-network-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 05 Jul 2011 09:25:48 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Antispy Network]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2352</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Antispy Network adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsAntispyNetwork. Windows Antispy Network is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Antispy Network </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispyNetwork"><strong>Adware.Win32.WindowsAntispyNetwork</strong></a><strong>.</strong></p>
<p><strong> Windows Antispy Network </strong>is   a                                     rogue           application.                                                            A         rogue                        application       tries      to       trick  you   by                                          displaying                            false                                      positive/misleading             scan                             results                           report,   which      says                      that   your                                                   computer          has  a          problem,             or      infected         with                                  viruses         or                 trojan,          but       you        will                   not             be         able                to   fix     it                 before       you                           purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong> Windows Antidanger Center</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong>Windows Accelerating Utility</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWorkChecker" target="_blank"><strong>Windows Work Checker</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMonitoringUtility"><strong> Windows Monitoring Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExaminationUtility"><strong>Windows Examination Utility</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesKiller"><strong>Windows Troubles Killer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionAlarm"><strong>Windows Protection Alarm</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRescueCenter" target="_blank"><strong>Windows Rescue Center</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrashesDeliverer"><strong>Windows Crashes Deliverer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSaviourFirewall"><strong>Windows Saviour Firewall</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAvertingSystem"><strong>Windows Averting System</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccidentsPrevention"><strong>Windows Accidents Prevention</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver"><strong>Windows Troubles Solver</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Windows Anticrashes Utility</strong></a></li>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong></strong><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntispyNetwork_1.png"><img class="alignnone size-medium wp-image-2354" title="Adware.Win32.WindowsAntispyNetwork" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntispyNetwork_1-400x208.png" alt="Adware.Win32.WindowsAntispyNetwork" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntispyNetwork_2.png"><img class="alignnone size-medium wp-image-2355" title="Adware.Win32.WindowsAntispyNetwork" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntispyNetwork_2-400x208.png" alt="Adware.Win32.WindowsAntispyNetwork" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntispyNetwork_3.png"><img class="alignnone size-medium wp-image-2356" title="Adware.Win32.WindowsAntispyNetwork" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntispyNetwork_3-400x228.png" alt="Adware.Win32.WindowsAntispyNetwork" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntispyNetwork_4.png"><img class="alignnone size-medium wp-image-2357" title="Adware.Win32.WindowsAntispyNetwork" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntispyNetwork_4-400x228.png" alt="Adware.Win32.WindowsAntispyNetwork" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntispyNetwork_5.png"><img class="alignnone size-medium wp-image-2358" title="Adware.Win32.WindowsAntispyNetwork" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntispyNetwork_5-400x235.png" alt="Adware.Win32.WindowsAntispyNetwork" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntispyNetwork_6.png"><img class="alignnone size-medium wp-image-2359" title="Adware.Win32.WindowsAntispyNetwork" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntispyNetwork_6-400x214.png" alt="Adware.Win32.WindowsAntispyNetwork" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntispyNetwork_7.png"><img class="alignnone size-medium wp-image-2360" title="Adware.Win32.WindowsAntispyNetwork" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntispyNetwork_7-400x214.png" alt="Adware.Win32.WindowsAntispyNetwork" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntispyNetwork_8.png"><img class="alignnone size-medium wp-image-2361" title="Adware.Win32.WindowsAntispyNetwork" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntispyNetwork_8-400x211.png" alt="Adware.Win32.WindowsAntispyNetwork" width="400" height="211" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntispyNetwork_9.png"><img class="alignnone size-medium wp-image-2362" title="Adware.Win32.WindowsAntispyNetwork" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/07/Adware.Win32.WindowsAntispyNetwork_9-400x325.png" alt="Adware.Win32.WindowsAntispyNetwork" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows Antispy Network</strong><strong> </strong><strong> </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispyNetwork"><strong>Adware.Win32.</strong><strong>WindowsAntispyNetwork</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/22/windows-av-software-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows AV Software Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/07/05/windows-antispy-network-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Antidanger Center Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/06/28/windows-antidanger-center-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/06/28/windows-antidanger-center-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 28 Jun 2011 16:16:52 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Antidanger Center]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2341</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Antidanger Center adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsAntidangerCenter. Windows Antidanger Center is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Antidanger Center </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong>Adware.Win32.WindowsAntidangerCenter</strong></a><strong>.</strong></p>
<p><strong> Windows Antidanger Center</strong> is   a                                    rogue           application.                                                           A         rogue                       application       tries      to       trick  you   by                                         displaying                            false                                     positive/misleading             scan                            results                           report,   which     says                      that   your                                                  computer          has  a          problem,            or      infected         with                                  viruses        or                 trojan,          but       you        will                  not             be         able                to   fix    it                 before       you                           purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility"><strong> Windows Accelerating Utility</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWorkChecker" target="_blank"><strong>Windows Work Checker</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMonitoringUtility"><strong> Windows Monitoring Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExaminationUtility"><strong>Windows Examination Utility</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesKiller"><strong>Windows Troubles Killer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionAlarm"><strong>Windows Protection Alarm</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRescueCenter" target="_blank"><strong>Windows Rescue Center</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrashesDeliverer"><strong>Windows Crashes Deliverer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSaviourFirewall"><strong>Windows Saviour Firewall</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAvertingSystem"><strong>Windows Averting System</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccidentsPrevention"><strong>Windows Accidents Prevention</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver"><strong>Windows Troubles Solver</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Windows Anticrashes Utility</strong></a></li>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong></strong><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAntidangerCenter_1.png"><img class="alignnone size-medium wp-image-2342" title="Adware.Win32.WindowsAntidangerCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAntidangerCenter_1-400x208.png" alt="Adware.Win32.WindowsAntidangerCenter" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAntidangerCenter_2.png"><img class="alignnone size-medium wp-image-2343" title="Adware.Win32.WindowsAntidangerCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAntidangerCenter_2-400x208.png" alt="Adware.Win32.WindowsAntidangerCenter" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAntidangerCenter_3.png"><img class="alignnone size-medium wp-image-2344" title="Adware.Win32.WindowsAntidangerCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAntidangerCenter_3-400x228.png" alt="Adware.Win32.WindowsAntidangerCenter" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAntidangerCenter_4.png"><img class="alignnone size-medium wp-image-2345" title="Adware.Win32.WindowsAntidangerCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAntidangerCenter_4-400x228.png" alt="Adware.Win32.WindowsAntidangerCenter" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAntidangerCenter_5.png"><img class="alignnone size-medium wp-image-2346" title="Adware.Win32.WindowsAntidangerCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAntidangerCenter_5-400x235.png" alt="Adware.Win32.WindowsAntidangerCenter" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAntidangerCenter_6.png"><img class="alignnone size-medium wp-image-2347" title="Adware.Win32.WindowsAntidangerCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAntidangerCenter_6-400x214.png" alt="Adware.Win32.WindowsAntidangerCenter" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAntidangerCenter_7.png"><img class="alignnone size-medium wp-image-2348" title="Adware.Win32.WindowsAntidangerCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAntidangerCenter_7-400x214.png" alt="Adware.Win32.WindowsAntidangerCenter" width="400" height="214" /></a></strong></p>
<p><strong>How to remove the infection of Windows Antidanger Center</strong><strong> </strong><strong> </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntidangerCenter"><strong>Adware.Win32.</strong><strong>WindowsAntidangerCenter</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-defence-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Defence Center Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/06/28/windows-antidanger-center-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Accelerating Utility Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/06/23/windows-accelerating-utility-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/06/23/windows-accelerating-utility-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 23 Jun 2011 12:05:58 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Accelerating Utility]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2329</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Accelerating Utility adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsAcceleratingUtility. Windows Accelerating Utility is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Accelerating Utility </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility" target="_blank"><strong>Adware.Win32.WindowsAcceleratingUtility</strong></a><strong>.</strong></p>
<p><strong> Windows Accelerating Utility</strong> is   a                                   rogue           application.                                                          A         rogue                      application       tries      to       trick  you   by                                        displaying                            false                                    positive/misleading             scan                           results                           report,   which    says                      that   your                                                 computer          has  a          problem,            or     infected         with                                  viruses       or                 trojan,          but       you        will                 not             be         able                to   fix    it                before       you                           purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWorkChecker" target="_blank"><strong>Windows Work Checker</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMonitoringUtility"><strong> Windows Monitoring Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExaminationUtility"><strong>Windows Examination Utility</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesKiller"><strong>Windows Troubles Killer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionAlarm"><strong>Windows Protection Alarm</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRescueCenter" target="_blank"><strong>Windows Rescue Center</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrashesDeliverer"><strong>Windows Crashes Deliverer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSaviourFirewall"><strong>Windows Saviour Firewall</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAvertingSystem"><strong>Windows Averting System</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccidentsPrevention"><strong>Windows Accidents Prevention</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver"><strong>Windows Troubles Solver</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Windows Anticrashes Utility</strong></a></li>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong></strong><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAcceleratingUtility_1.png"><img class="alignnone size-medium wp-image-2330" title="Adware.Win32.WindowsAcceleratingUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAcceleratingUtility_1-400x208.png" alt="Adware.Win32.WindowsAcceleratingUtility" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAcceleratingUtility_2.png"><img class="alignnone size-medium wp-image-2331" title="Adware.Win32.WindowsAcceleratingUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAcceleratingUtility_2-400x208.png" alt="Adware.Win32.WindowsAcceleratingUtility" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAcceleratingUtility_3.png"><img class="alignnone size-medium wp-image-2332" title="Adware.Win32.WindowsAcceleratingUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAcceleratingUtility_3-400x214.png" alt="Adware.Win32.WindowsAcceleratingUtility" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAcceleratingUtility_4.png"><img class="alignnone size-medium wp-image-2333" title="Adware.Win32.WindowsAcceleratingUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAcceleratingUtility_4-400x228.png" alt="Adware.Win32.WindowsAcceleratingUtility" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAcceleratingUtility_5.png"><img class="alignnone size-medium wp-image-2334" title="Adware.Win32.WindowsAcceleratingUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAcceleratingUtility_5-400x214.png" alt="Adware.Win32.WindowsAcceleratingUtility" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAcceleratingUtility_6.png"><img class="alignnone size-medium wp-image-2335" title="Adware.Win32.WindowsAcceleratingUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAcceleratingUtility_6-400x228.png" alt="Adware.Win32.WindowsAcceleratingUtility" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAcceleratingUtility_7.png"><img class="alignnone size-medium wp-image-2336" title="Adware.Win32.WindowsAcceleratingUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAcceleratingUtility_7-400x211.png" alt="Adware.Win32.WindowsAcceleratingUtility" width="400" height="211" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAcceleratingUtility_8.png"><img class="alignnone size-medium wp-image-2337" title="Adware.Win32.WindowsAcceleratingUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAcceleratingUtility_8-400x235.png" alt="Adware.Win32.WindowsAcceleratingUtility" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAcceleratingUtility_9.png"><img class="alignnone size-medium wp-image-2338" title="Adware.Win32.WindowsAcceleratingUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAcceleratingUtility_9-400x325.png" alt="Adware.Win32.WindowsAcceleratingUtility" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows Accelerating Utility</strong><strong> </strong><strong> </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAcceleratingUtility" target="_blank"><strong>Adware.Win32.WindowsAcceleratingUtility</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/06/28/windows-antidanger-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Antidanger Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/06/23/windows-accelerating-utility-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>System Smart Security Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/06/11/system-smart-security-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/06/11/system-smart-security-adware-removal-instructions/#comments</comments>
		<pubDate>Sat, 11 Jun 2011 05:09:45 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[System Smart Security]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2322</guid>
		<description><![CDATA[The Emsisoft malware research team has discoverd a new outbreak of the System Smart Security adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.SystemSmartSecurity. System Smart Security is a rogue security software that show false warning messages and show misleading scan results, this is another variant from Smart Engine, Smart Security, My Security Shield, Security Master [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft</strong> malware research team has           discoverd a new outbreak           of the<strong> System Smart Security </strong>adware.    <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft                     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemSmartSecurity" target="_blank"><strong>Adware.Win32.SystemSmartSecurity</strong></a>.</p>
<p><strong>System Smart Security </strong>is a rogue security software that       show false  warning  messages and show misleading scan results, this      is another variant from <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartEngine" target="_blank"><strong>Smart Engine</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartSecurity" target="_blank"><strong>Smart Security</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MySecurityShield" target="_blank"><strong>My Security Shield</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecurityMasterAV" target="_blank"><strong>Security Master AV</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MySecurityEngine" target="_blank"><strong>My Security Engine</strong></a>, or <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.CleanUPAntivirus" target="_blank"><strong>CleanUP Antivirus</strong></a>.     It will  start   automatically when your computer starts. The      installer will also   create  numerous harmless files on your computer,      usually at Recent   folder,  that are used to impersonate malware     files.  Once the program   is running  it will scan your computer and     then display  these files as   infections,  but will not allow you to     remove them until  you purchase   the program.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\73f1ad\</li>
<li>%AllUsersProfile%\Application Data\73f1ad\SS73f_2121.exe</li>
<li>%AllUsersProfile%\Application Data\73f1ad\SSS.ico</li>
<li>%AllUsersProfile%\Application Data\73f1ad\Quarantine Items\</li>
<li>%AllUsersProfile%\Application Data\73f1ad\SSSSys\</li>
<li>%AllUsersProfile%\Application Data\SSXPJHOS\</li>
<li>%AllUsersProfile%\Application Data\SSXPJHOS\SSGRCS.cfg</li>
<li>%UserProfile%\Desktop\System Smart Security.lnk</li>
<li>%UserProfile%\Recent\exec.exe</li>
<li>%UserProfile%\Recent\fix.exe</li>
<li>%UserProfile%\Recent\kernel32.exe</li>
<li>%UserProfile%\Recent\PE.dll</li>
<li>%UserProfile%\Recent\PE.drv</li>
<li>%UserProfile%\Recent\runddl.exe</li>
<li>%UserProfile%\Recent\SICKBOY.drv</li>
<li>%UserProfile%\Recent\sld.drv</li>
<li>%UserProfile%\Recent\tjd.dll</li>
<li>%UserProfile%\Recent\tjd.sys</li>
<li>%UserProfile%\Recent\ANTIGEN.dll</li>
<li>%UserProfile%\Recent\ANTIGEN.drv</li>
<li>%UserProfile%\Recent\cid.drv</li>
<li>%UserProfile%\Recent\ddv.drv</li>
<li>%UserProfile%\Start Menu\System Smart Security.lnk</li>
<li>%UserProfile%\Start Menu\Programs\System Smart Security.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ProgID\: &#8220;SS73f_2121.DocHostUIHandler&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\LocalServer32\: &#8220;C:\DOCUME~1\ALLUSE~1\APPLIC~1\73f1ad\SS73F_~1.EXE&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\: &#8220;Implements DocHostUIHandler&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SS73f_2121.DocHostUIHandler\Clsid\: &#8220;{3F2BBC05-40DF-11D2-9455-00104BC936FF}&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SS73f_2121.DocHostUIHandler\: &#8220;Implements DocHostUIHandler&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\install.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AluSchedulerSvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\amon9x.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\anti-trojan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirus.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ants.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\apimonitor.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aplica32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\apvxdwin.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\arr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Arrakis3.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashAvast.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashBug.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashChest.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashCnsnt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashLogV.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashMaiSv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashPopWz.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashQuick.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashServ.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSimp2.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSimpl.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSkPcc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSkPck.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashUpd.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashWebSv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswChLic.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswRegSvr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswRunDll.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswUpdSv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\atcon.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\atguard.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\atro55en.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\atupdater.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\atwatch.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\au.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aupdate.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\auto-protect.nav80try.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\autodown.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\autotrace.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoupdate.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avadmin.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avcenter.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avciman.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconfig.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconsol.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ave32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcc32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgchk.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcmgr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcsrvx.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgctrl.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgdumpx.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgemc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgiproxy.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnsx.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrsx.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgscanx.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgserv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgserv9.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgsrmax.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgtray.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgui.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgupd.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgwdsvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkpop.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkserv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkservice.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkwctl9.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avltmain.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avmailc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avmcdlg.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avnotify.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avnt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpcc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpdos32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpm.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avptc32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpupd.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avsched32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avsynmgr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avupgsvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVWEBGRD.EXE\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwin.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwin95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwinnt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwsc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupd.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupd32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupsrv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxmonitor9x.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxmonitornt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxquar.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\b.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\backweb.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bargains.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdagent.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvcl.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvwiz.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDInProcPatch.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdmcon.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDMsnScan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdreinit.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdsubwiz.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDSurvey.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdtkexec.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdwizreg.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bd_professional.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\beagle.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\belt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bidef.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bidserver.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bipcp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bipcpevalsetup.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bisp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\blackd.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\blackice.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\blink.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\blss.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bootconf.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bootwarn.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\borg2.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\brasil.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\brw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bs120.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bspatch.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bundle.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bvt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\c.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cavscan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccapp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccevtmgr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccpxysvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccSvcHst.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cdp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfd.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfgwiz.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfiadmin.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfiaudit.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfinet.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfinet32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfpconfg.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfplogvw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfpupdat.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cl.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\claw95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\claw95cf.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\clean.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleaner.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleaner3.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleanIELow.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleanpc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\click.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmdagent.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmesys.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmgrdian.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmon016.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\connectionmonitor.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\control\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpd.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpf9x206.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpfnt206.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\crashrep.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssconfg.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssupdat.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssurf.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctrl.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cwnb181.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cwntdwmo.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\d.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\datemanager.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dcomx.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\defalert.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\defscangui.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\defwatch.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deloeminfs.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deputy.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dllcache.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dllreg.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\doors.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpf.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpfsetup.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpps2.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\driverctrl.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\drwatson.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\drweb32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\drwebupw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dssagent.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dvp95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dvp95_0.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ecengine.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\efpeadm.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\emsw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ent.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\esafe.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\escanhnt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\escanv95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\espwatch.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ethereal.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\etrustcipe.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\evpn.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\exantivirus-cnet.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\exe.avxw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\expert.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explore.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-agnt95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-prot.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-prot95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-stopw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fact.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fameh32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fast.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fch32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fih32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\findviru.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\firewall.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fixcfg.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fixfp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fnrb32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fp-win.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fp-win_trial.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fprot.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\frmwrk32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\frw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsaa.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav530stbyb.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav530wtbyb.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsgk32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsm32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsma32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsmb32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gator.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gav.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbmenu.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbpoll.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\generics.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gmt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\guard.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\guarddog.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\guardgui.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hacktracersetup.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hbinst.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hbsrv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\History.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\homeav2010.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hotactio.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hotpatch.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\htlog.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\htpatch.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hwpe.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hxdl.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hxiul.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamapp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamserv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamstats.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ibmasn.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ibmavsp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\icload95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\icloadnt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\icmon.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\icsupp95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\icsuppnt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Identity.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\idle.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iedll.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iedriver.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IEShow.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iface.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ifw2000.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\inetlnfo.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\infus.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\infwin.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\init.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\init32.exe \Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[1].exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[2].exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[3].exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[4].exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[5].exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\intdel.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\intren.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iomon98.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\istsvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jammer.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jdbgmrg.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jedi.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\JsRcGen.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavlite40eng.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavpers40eng.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavpf.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kazza.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\keenvalue.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-pf-213-en-win.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-wrl-421-en-win.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-wrp-421-en-win.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\killprocesssetup161.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldnetmon.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldpro.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldpromenu.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldscan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\licmgr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\livesrv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lnetinfo.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\loader.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\localnet.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lockdown.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lockdown2000.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lookout.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lordpe.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lsetup.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\luall.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\luau.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lucomserver.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\luinit.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\luspt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MalwareRemoval.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mapisvc32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcagent.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcmnhdlr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcmscsvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcnasvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcproxy.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\McSACore.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcshell.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcshield.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcsysmon.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mctool.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcupdate.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcvsrte.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcvsshld.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\md.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfin32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfw2en.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfweng3.02d30.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgavrtcl.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgavrte.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mghtml.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgui.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\minilog.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmod.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\monitor.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\moolive.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpfagent.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpfservice.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MPFSrv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpftray.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mrflux.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mrt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msa.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msapp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msbb.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msblast.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscache.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msccn32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscman.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msdm.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msdos.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msfwsvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msiexec16.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mslaugh.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmgt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MsMpEng.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmsgri32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mssmmc32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mssys.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msvxd.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mu0311ad.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mwatch.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\n32scanw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nav.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\navap.navapsvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\navapsvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\navapw32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\navdx.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\navlu32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\navnt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\navstub.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\navw32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\navwnt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nc2000.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ncinst4.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ndd32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\neomonitor.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\neowatchlog.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\netarmor.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\netd32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\netinfo.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\netmon.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\netscanpro.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\netspyhunter-1.2.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\netutils.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nisserv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nisum.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nmain.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\normist.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\norton_internet_secu_3.0_407.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\notstart.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\npf40_tw_98_nt_me_2k.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\npfmessenger.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nprotect.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\npscheck.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\npssvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nsched32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nssys32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nstask32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nsupdate.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntrtscan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntvdm.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntxconfig.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nui.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nupgrade.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvarch16.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvc95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvsvc32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwinst4.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwservice.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwtool16.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAcat.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAhlp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAReg.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\oasrv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\oaui.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\oaview.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OcHealthMon.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ODSW.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ollydbg.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OLT.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onsrvr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\optimize.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ostronet.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\otfix.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpost.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpostinstall.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpostproinstall.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ozn695m5.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\padmin.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\panixk.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\patch.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pav.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavcl.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PavFnSvr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavproxy.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavprsrv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavsched.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavsrv51.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pccwin98.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcfwallicon.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcip10117_0.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcscan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsAuxs.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsGui.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsSvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsTray.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PC_Antispyware2010.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfndr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdsetup.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PerAvir.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\periscope.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\persfw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\perswf.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pf2.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pfwadmin.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pgmonitr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pingscan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pop3trap.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\poproxy.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\popscan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\portdetective.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\portmonitor.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerscan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ppinupdt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pptbc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ppvstop.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\prizesurfer.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\prmt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\prmvr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\procdump.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\processmonitor.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexplorerv1.0.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\programauditor.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\proport.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protector.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectx.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANCU.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANHost.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANToManager.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PsCtrls.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PsImSvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PskSvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pspf.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSUNMain.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\purge.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qconsole.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qh.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qserver.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quick Heal.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QuickHealCleaner.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rapapp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav7.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav7win.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav8win32eng.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ray.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rb32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rcsync.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\realmon.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\reged.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedt32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rescue.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rescue32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rrguard.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rscdwld.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rshell.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rtvscan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rtvscn95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rulaunch.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeweb.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sahagent.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Save.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveArmor.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveDefense.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveKeep.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\savenow.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sbserv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scam32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scanpm.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scrscan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\seccenter.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secure Veteran.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\secureveteran.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Security Center.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SecurityFighter.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\securitysoldier.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\serv95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setloadorder.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setupvameeval.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup_flowprotector_us.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sgssfw32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sh.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shellspyinstall.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shield.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shn.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\showbehind.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\signcheck.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smart.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartprotector.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smrtdefp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sms.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smss32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snetcfg.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\soap.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sofi.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftSafeness.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sperm.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spf.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sphinx.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoler.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolcv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolsv32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spywarexpguard.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spyxx.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\srexe.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\srng.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ss3edit.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssgrate.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssg_4104.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\st2.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\start.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stcloader.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\supftrl.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\support.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\supporter5.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchostc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchosts.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svshost.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweep95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweepnet.sweepsrv.sys.swnetsup.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcsvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\symproxysvc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\symtray.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\system.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\system32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sysupd.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taumon.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbscan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tca.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tcm.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds-3.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds2-98.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds2-nt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\teekids.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tfak.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tfak5.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tgbob.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\titanin.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\titaninxp.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TPSrv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\trickler.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\trjscan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\trjsetup.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\trojantrap3.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrustWarrior.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsadbot.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tvmd.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tvtmd.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uiscan.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\undoboot.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\updat.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\upgrad.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\upgrepl.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utpost.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbcmserv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbcons.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbust.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbwin9x.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbwinntw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vcsetup.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vet32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vet95.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vettray.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vfsetup.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vir-help.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\virusmdpersonalfirewall.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthAux.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthLic.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthUpd.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vnlan300.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vnpc3000.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpc32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpc42.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpfw30s.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vptray.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vscan40.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vscenu6.02d30.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsched.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsecomr.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vshwin32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsisetup.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsmain.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsmon.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsserv.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsstat.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswin9xe.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswinntse.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswinperse.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\w32dsm89.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\W3asbas.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\w9x.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\watchdog.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\webdav.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WebProxy.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\webscanx.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\webtrap.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wfindv32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\whoswatchingme.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wimmun32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\win-bugsfix.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\win32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\win32us.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winactive.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winav.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\windll32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\window.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows Police Pro.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wininetd.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wininitx.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winlogin.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winmain.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winppr32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winrecon.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winservn.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winss.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winssk32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winssnotify.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WinSSUI.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winstart.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winstart001.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wintsk32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winupdate.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wkufind.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wnad.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wnt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wradmin.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wrctrl.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsbgate.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxas.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxav.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxfw.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsctool.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wupdater.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wupdt.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wyvernworksfirewall.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpdeluxe.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpf202en.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapro.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zatutor.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zonalm2601.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zonealarm.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpm.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\~1.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\~2.exe\Debugger: &#8220;svchost.exe&#8221;</li>
<li>HKEY_USER\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\URL: &#8220;http://findgala.com/?&amp;uid=2121&amp;q={searchTerms}&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IIL: 0&#215;00000000</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\ltHI: 0&#215;00000000</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\ltTST: 0x00008BC3</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PRS: &#8220;http://127.0.0.1:27777/?inj=%ORIGINAL%&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\RunInvalidSignatures: 0&#215;00000001</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\CpMRU\Enable: 0&#215;00000001</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\CpMRU\Size: 0x0000000A</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\CpMRU\InitHits: 0&#215;00000064</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\CpMRU\Factor: 0&#215;00000014</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation\MSCompatibilityMode: 0&#215;00000000</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\URL: &#8220;http://findgala.com/?&amp;uid=2121&amp;q={searchTerms}&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\UID: &#8220;2121&#8243;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer: &#8220;http=127.0.0.1:25430&#8243;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\78690298603: &#8220;&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\Version/12.02121: &#8220;&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun: 0&#215;00000001</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\0: &#8220;msseces.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\1: &#8220;MSASCui.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\2: &#8220;ekrn.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\3: &#8220;egui.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\4: &#8220;avgnt.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\5: &#8220;avcenter.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\6: &#8220;avscan.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\7: &#8220;avgfrw.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\8: &#8220;avgui.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\9: &#8220;avgtray.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\10: &#8220;avgscanx.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\11: &#8220;avgcfgex.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\12: &#8220;avgemc.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\13: &#8220;avgchsvx.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\14: &#8220;avgcmgr.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\15: &#8220;avgwdsvc.exe&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\System Smart Security: &#8220;&#8221;%AllUsersProfile%\Application Data\73f1ad\SS73f_2121.exe&#8221; /s /d&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes\URL: &#8220;http://findgala.com/?&amp;uid=2121&amp;q={searchTerms}&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\CheckExeSignatures: &#8220;no&#8221;</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable: 0&#215;00000001</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.SystemSmartSecurity_1.png"><img class="alignnone size-medium wp-image-2323" title="Adware.Win32.SystemSmartSecurity" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.SystemSmartSecurity_1-400x202.png" alt="Adware.Win32.SystemSmartSecurity" width="400" height="202" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.SystemSmartSecurity_2.png"><img class="alignnone size-medium wp-image-2324" title="Adware.Win32.SystemSmartSecurity" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.SystemSmartSecurity_2-400x290.png" alt="Adware.Win32.SystemSmartSecurity" width="400" height="290" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.SystemSmartSecurity_3.png"><img class="alignnone size-medium wp-image-2325" title="Adware.Win32.SystemSmartSecurity" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.SystemSmartSecurity_3-400x225.png" alt="Adware.Win32.SystemSmartSecurity" width="400" height="225" /></a></p>
<p><strong>How to remove the infection of System Smart Security </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemSmartSecurity" target="_blank">Adware.Win32.SystemSmartSecurity</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Smart Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/12/26/home-security-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Home Security Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/03/22/cleanup-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">CleanUP Antivirus Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/06/11/system-smart-security-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Personal Shield Pro Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/06/11/personal-shield-pro-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/06/11/personal-shield-pro-adware-removal-instructions/#comments</comments>
		<pubDate>Sat, 11 Jun 2011 04:22:23 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Personal Shield Pro]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2311</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Personal Shield Pro adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.PersonalShieldPro. Personal Shield Pro is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Personal Shield Pro </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PersonalShieldPro"><strong>Adware.Win32.PersonalShieldPro</strong></a><strong>.</strong></p>
<p><strong>Personal Shield Pro</strong> is   a                                   rogue           application.                                                          A         rogue                      application       tries      to       trick  you   by                                        displaying                            false                                    positive/misleading             scan                           results                           report,   which    says                      that   your                                                 computer          has  a          problem,            or     infected         with                                  viruses       or                 trojan,          but       you        will                 not             be         able                to   fix    it                before       you                           purchase.</p>
<p><strong>Create new file:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\%random%.exe</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run<br />
(String) %random% = %AllUsersProfile%\Application Data\%random%.exe &#8211;run</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.PersonalShieldPro_2.png"><img class="alignnone size-medium wp-image-2313" title="Adware.Win32.PersonalShieldPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.PersonalShieldPro_2-400x256.png" alt="Adware.Win32.PersonalShieldPro" width="400" height="256" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.PersonalShieldPro_4.png"><img class="alignnone size-medium wp-image-2315" title="Adware.Win32.PersonalShieldPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.PersonalShieldPro_4-400x316.png" alt="Adware.Win32.PersonalShieldPro" width="400" height="316" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.PersonalShieldPro_5.png"><img class="alignnone size-medium wp-image-2316" title="Adware.Win32.PersonalShieldPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.PersonalShieldPro_5-400x354.png" alt="Adware.Win32.PersonalShieldPro" width="400" height="354" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.PersonalShieldPro_6.png"><img class="alignnone size-medium wp-image-2317" title="Adware.Win32.PersonalShieldPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.PersonalShieldPro_6-400x283.png" alt="Adware.Win32.PersonalShieldPro" width="400" height="283" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.PersonalShieldPro_7.png"><img class="alignnone size-medium wp-image-2318" title="Adware.Win32.PersonalShieldPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.PersonalShieldPro_7-400x229.png" alt="Adware.Win32.PersonalShieldPro" width="400" height="229" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.PersonalShieldPro_8.png"><img class="alignnone size-medium wp-image-2319" title="Adware.Win32.PersonalShieldPro" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.PersonalShieldPro_8-400x251.png" alt="Adware.Win32.PersonalShieldPro" width="400" height="251" /></a></p>
<p><strong>How to remove the infection of Personal Shield Pro</strong><strong> </strong><strong> </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PersonalShieldPro" target="_blank"><strong>Adware.Win32.PersonalShieldPro</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/07/24/security-shield-adware-removal-instructions-2/" rel="bookmark" class="crp_title">Security Shield Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/19/security-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/09/23/total-protect-adware-removal-instructions/" rel="bookmark" class="crp_title">Total Protect Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/01/11/palladium-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Palladium Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/04/13/antivirus-clean-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Clean 2011 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/06/11/personal-shield-pro-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Work Checker Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/06/10/windows-work-checker-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/06/10/windows-work-checker-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 10 Jun 2011 19:53:05 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Work Checker]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2297</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Work Checker adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsWorkChecker. Windows Work Checker is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Work Checker </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWorkChecker"><strong>Adware.Win32.WindowsWorkChecker</strong></a><strong>.</strong></p>
<p><strong> Windows Work Checker</strong> is   a                                  rogue           application.                                                         A         rogue                      application      tries      to       trick  you   by                                       displaying                            false                                   positive/misleading             scan                          results                           report,   which    says                     that   your                                                computer          has  a          problem,            or     infected        with                                  viruses       or                trojan,          but       you        will                 not            be         able                to   fix    it                before      you                           purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMonitoringUtility"><strong> Windows Monitoring Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExaminationUtility"><strong>Windows Examination Utility</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesKiller"><strong>Windows Troubles Killer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionAlarm"><strong>Windows Protection Alarm</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRescueCenter" target="_blank"><strong>Windows Rescue Center</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrashesDeliverer"><strong>Windows Crashes Deliverer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSaviourFirewall"><strong>Windows Saviour Firewall</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAvertingSystem"><strong>Windows Averting System</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccidentsPrevention"><strong>Windows Accidents Prevention</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver"><strong>Windows Troubles Solver</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Windows Anticrashes Utility</strong></a></li>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong></strong><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsWorkChecker_1.png"><img class="alignnone size-medium wp-image-2298" title="Adware.Win32.WindowsWorkChecker" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsWorkChecker_1-400x208.png" alt="Adware.Win32.WindowsWorkChecker" width="400" height="208" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsWorkChecker_2.png"><img class="alignnone size-medium wp-image-2299" title="Adware.Win32.WindowsWorkChecker" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsWorkChecker_2-400x208.png" alt="Adware.Win32.WindowsWorkChecker" width="400" height="208" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsWorkChecker_3.png"><img class="alignnone size-medium wp-image-2300" title="Adware.Win32.WindowsWorkChecker" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsWorkChecker_3-400x228.png" alt="Adware.Win32.WindowsWorkChecker" width="400" height="228" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsWorkChecker_4.png"><img class="alignnone size-medium wp-image-2301" title="Adware.Win32.WindowsWorkChecker" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsWorkChecker_4-400x228.png" alt="Adware.Win32.WindowsWorkChecker" width="400" height="228" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsWorkChecker_5.png"><img class="alignnone size-medium wp-image-2302" title="Adware.Win32.WindowsWorkChecker" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsWorkChecker_5-400x235.png" alt="Adware.Win32.WindowsWorkChecker" width="400" height="235" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsWorkChecker_6.png"><img class="alignnone size-medium wp-image-2303" title="Adware.Win32.WindowsWorkChecker" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsWorkChecker_6-400x214.png" alt="Adware.Win32.WindowsWorkChecker" width="400" height="214" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsWorkChecker_7.png"><img class="alignnone size-medium wp-image-2304" title="Adware.Win32.WindowsWorkChecker" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsWorkChecker_7-400x214.png" alt="Adware.Win32.WindowsWorkChecker" width="400" height="214" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsWorkChecker_8.png"><img class="alignnone size-medium wp-image-2305" title="Adware.Win32.WindowsWorkChecker" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsWorkChecker_8-400x211.png" alt="Adware.Win32.WindowsWorkChecker" width="400" height="211" /></a></p>
<p><strong>How to remove the infection of Windows Work Checker</strong><strong> </strong><strong> </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWorkChecker"><strong>Adware.Win32.WindowsWorkChecker</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/06/28/windows-antidanger-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Antidanger Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/06/10/windows-work-checker-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Monitoring Utility Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/06/10/windows-monitoring-utility-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/06/10/windows-monitoring-utility-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 10 Jun 2011 19:52:20 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Monitoring Utility]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2286</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Monitoring Utility adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsMonitoringUtility. Windows Monitoring Utility is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Monitoring Utility </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMonitoringUtility"><strong>Adware.Win32.WindowsMonitoringUtility</strong></a><strong>.</strong></p>
<p><strong> Windows Monitoring Utility</strong> is   a                                 rogue           application.                                                        A         rogue                     application      tries      to       trick  you   by                                      displaying                            false                                  positive/misleading             scan                         results                           report,   which    says                    that   your                                               computer          has  a          problem,            or     infected       with                                  viruses       or               trojan,          but       you        will                 not           be         able                to   fix    it                before     you                           purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExaminationUtility"><strong>Windows Examination Utility</strong><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesKiller"><strong>Windows Troubles Killer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionAlarm"><strong>Windows Protection Alarm</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRescueCenter" target="_blank"><strong>Windows Rescue Center</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrashesDeliverer"><strong>Windows Crashes Deliverer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSaviourFirewall"><strong>Windows Saviour Firewall</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAvertingSystem"><strong>Windows Averting System</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccidentsPrevention"><strong>Windows Accidents Prevention</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver"><strong>Windows Troubles Solver</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Windows Anticrashes Utility</strong></a></li>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong></strong><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsMonitoringUtility_1.png"><img class="alignnone size-medium wp-image-2288" title="Adware.Win32.WindowsMonitoringUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsMonitoringUtility_1-400x208.png" alt="Adware.Win32.WindowsMonitoringUtility" width="400" height="208" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsMonitoringUtility_2.png"><img class="alignnone size-medium wp-image-2289" title="Adware.Win32.WindowsMonitoringUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsMonitoringUtility_2-400x208.png" alt="Adware.Win32.WindowsMonitoringUtility" width="400" height="208" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsMonitoringUtility_3.png"><img class="alignnone size-medium wp-image-2290" title="Adware.Win32.WindowsMonitoringUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsMonitoringUtility_3-400x228.png" alt="Adware.Win32.WindowsMonitoringUtility" width="400" height="228" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsMonitoringUtility_4.png"><img class="alignnone size-medium wp-image-2291" title="Adware.Win32.WindowsMonitoringUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsMonitoringUtility_4-400x228.png" alt="Adware.Win32.WindowsMonitoringUtility" width="400" height="228" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsMonitoringUtility_5.png"><img class="alignnone size-medium wp-image-2292" title="Adware.Win32.WindowsMonitoringUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsMonitoringUtility_5-400x235.png" alt="Adware.Win32.WindowsMonitoringUtility" width="400" height="235" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsMonitoringUtility_6.png"><img class="alignnone size-medium wp-image-2293" title="Adware.Win32.WindowsMonitoringUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsMonitoringUtility_6-400x214.png" alt="Adware.Win32.WindowsMonitoringUtility" width="400" height="214" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsMonitoringUtility_7.png"><img class="alignnone size-medium wp-image-2294" title="Adware.Win32.WindowsMonitoringUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsMonitoringUtility_7-400x214.png" alt="Adware.Win32.WindowsMonitoringUtility" width="400" height="214" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsMonitoringUtility_8.png"><img class="alignnone size-medium wp-image-2295" title="Adware.Win32.WindowsMonitoringUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsMonitoringUtility_8-400x209.png" alt="Adware.Win32.WindowsMonitoringUtility" width="400" height="209" /></a></p>
<p><strong>How to remove the infection of Windows Monitoring Utility</strong><strong> </strong><strong> </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMonitoringUtility"><strong>Adware.Win32.WindowsMonitoringUtility</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/06/28/windows-antidanger-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Antidanger Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/06/10/windows-monitoring-utility-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Examination Utility Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/06/10/windows-examination-utility-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/06/10/windows-examination-utility-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 10 Jun 2011 19:51:44 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Examination Utility]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2276</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Examination Utility adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsExaminationUtility. Windows Examination Utility is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Examination Utility </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExaminationUtility"><strong>Adware.Win32.WindowsExaminationUtility</strong></a><strong>.</strong></p>
<p><strong>Windows Examination Utility</strong><strong> </strong>is   a                                rogue           application.                                                       A         rogue                    application      tries      to       trick  you   by                                     displaying                            false                                 positive/misleading             scan                        results                           report,   which    says                   that   your                                              computer          has  a          problem,            or     infected      with                                  viruses       or              trojan,          but       you        will                 not          be         able                to   fix    it                before    you                           purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesKiller"><strong>Windows Troubles Killer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionAlarm"><strong>Windows Protection Alarm</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRescueCenter" target="_blank"><strong>Windows Rescue Center</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrashesDeliverer"><strong>Windows Crashes Deliverer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSaviourFirewall"><strong>Windows Saviour Firewall</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAvertingSystem"><strong>Windows Averting System</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccidentsPrevention"><strong>Windows Accidents Prevention</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver"><strong>Windows Troubles Solver</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Windows Anticrashes Utility</strong></a></li>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong></strong><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsExaminationUtility_1.png"><img class="alignnone size-medium wp-image-2277" title="Adware.Win32.WindowsExaminationUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsExaminationUtility_1-400x208.png" alt="Adware.Win32.WindowsExaminationUtility" width="400" height="208" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsExaminationUtility_2.png"><img class="alignnone size-medium wp-image-2278" title="Adware.Win32.WindowsExaminationUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsExaminationUtility_2-400x208.png" alt="Adware.Win32.WindowsExaminationUtility" width="400" height="208" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsExaminationUtility_3.png"><img class="alignnone size-medium wp-image-2279" title="Adware.Win32.WindowsExaminationUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsExaminationUtility_3-400x228.png" alt="Adware.Win32.WindowsExaminationUtility" width="400" height="228" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsExaminationUtility_4.png"><img class="alignnone size-medium wp-image-2280" title="Adware.Win32.WindowsExaminationUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsExaminationUtility_4-400x228.png" alt="Adware.Win32.WindowsExaminationUtility" width="400" height="228" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsExaminationUtility_5.png"><img class="alignnone size-medium wp-image-2281" title="Adware.Win32.WindowsExaminationUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsExaminationUtility_5-400x235.png" alt="Adware.Win32.WindowsExaminationUtility" width="400" height="235" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsExaminationUtility_6.png"><img class="alignnone size-medium wp-image-2282" title="Adware.Win32.WindowsExaminationUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsExaminationUtility_6-400x214.png" alt="Adware.Win32.WindowsExaminationUtility" width="400" height="214" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsExaminationUtility_7.png"><img class="alignnone size-medium wp-image-2283" title="Adware.Win32.WindowsExaminationUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsExaminationUtility_7-400x214.png" alt="Adware.Win32.WindowsExaminationUtility" width="400" height="214" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsExaminationUtility_8.png"><img class="alignnone size-medium wp-image-2284" title="Adware.Win32.WindowsExaminationUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsExaminationUtility_8-400x211.png" alt="Adware.Win32.WindowsExaminationUtility" width="400" height="211" /></a></p>
<p><strong>How to remove the infection of Windows Examination Utility</strong><strong> </strong><strong> </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExaminationUtility"><strong>Adware.Win32.WindowsExaminationUtility</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/06/10/windows-monitoring-utility-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Monitoring Utility Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/06/28/windows-antidanger-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Antidanger Center Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/06/10/windows-examination-utility-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Troubles Killer Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/06/10/windows-troubles-killer-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/06/10/windows-troubles-killer-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 10 Jun 2011 13:28:43 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Troubles Killer]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2264</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Troubles Killer adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsTroublesKiller. Windows Troubles Killer is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Troubles Killer </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesKiller"><strong>Adware.Win32.WindowsTroublesKiller</strong></a><strong>.</strong></p>
<p><strong>Windows Troubles Killer</strong><strong> </strong>is   a                               rogue           application.                                                      A         rogue                   application      tries      to       trick  you   by                                    displaying                            false                                positive/misleading             scan                       results                           report,   which    says                  that   your                                             computer          has  a          problem,            or     infected     with                                  viruses       or             trojan,          but       you        will                 not         be         able                to   fix    it                before   you                           purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionAlarm"><strong>Windows Protection Alarm</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRescueCenter" target="_blank"><strong>Windows Rescue Center</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrashesDeliverer"><strong>Windows Crashes Deliverer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSaviourFirewall"><strong>Windows Saviour Firewall</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAvertingSystem"><strong>Windows Averting System</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccidentsPrevention"><strong>Windows Accidents Prevention</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver"><strong>Windows Troubles Solver</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Windows Anticrashes Utility</strong></a></li>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong></strong><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesKiller_1.png"><img class="alignnone size-medium wp-image-2265" title="Adware.Win32.WindowsTroublesKiller" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesKiller_1-400x208.png" alt="Adware.Win32.WindowsTroublesKiller" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesKiller_2.png"><img class="alignnone size-medium wp-image-2266" title="Adware.Win32.WindowsTroublesKiller" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesKiller_2-400x208.png" alt="Adware.Win32.WindowsTroublesKiller" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesKiller_3.png"><img class="alignnone size-medium wp-image-2267" title="Adware.Win32.WindowsTroublesKiller" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesKiller_3-400x228.png" alt="Adware.Win32.WindowsTroublesKiller" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesKiller_4.png"><img class="alignnone size-medium wp-image-2268" title="Adware.Win32.WindowsTroublesKiller" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesKiller_4-400x228.png" alt="Adware.Win32.WindowsTroublesKiller" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesKiller_5.png"><img class="alignnone size-medium wp-image-2269" title="Adware.Win32.WindowsTroublesKiller" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesKiller_5-400x235.png" alt="Adware.Win32.WindowsTroublesKiller" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesKiller_6.png"><img class="alignnone size-medium wp-image-2270" title="Adware.Win32.WindowsTroublesKiller" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesKiller_6-400x214.png" alt="Adware.Win32.WindowsTroublesKiller" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesKiller_7.png"><img class="alignnone size-medium wp-image-2271" title="Adware.Win32.WindowsTroublesKiller" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesKiller_7-400x214.png" alt="Adware.Win32.WindowsTroublesKiller" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesKiller_8.png"><img class="alignnone size-medium wp-image-2272" title="Adware.Win32.WindowsTroublesKiller" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesKiller_8-400x211.png" alt="Adware.Win32.WindowsTroublesKiller" width="400" height="211" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesKiller_9.png"><img class="alignnone size-medium wp-image-2273" title="Adware.Win32.WindowsTroublesKiller" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesKiller_9-400x325.png" alt="Adware.Win32.WindowsTroublesKiller" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows Troubles Killer</strong><strong> </strong><strong> </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesKiller"><strong>Adware.Win32.WindowsTroublesKiller</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/16/windows-remedy-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Remedy Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/06/10/windows-troubles-killer-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Protection Alarm Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/06/10/windows-protection-alarm-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/06/10/windows-protection-alarm-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 10 Jun 2011 13:19:59 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Protection Alarm]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2252</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Protection Alarm adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsProtectionAlarm. Windows Protection Alarm is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Protection Alarm </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionAlarm" target="_blank"><strong>Adware.Win32.WindowsProtectionAlarm</strong></a><strong>.</strong></p>
<p><strong>Windows Protection Alarm</strong><strong> </strong>is   a                              rogue           application.                                                     A         rogue                  application      tries      to       trick  you   by                                   displaying                            false                               positive/misleading             scan                      results                           report,   which    says                 that   your                                             computer         has  a          problem,            or     infected     with                                 viruses       or             trojan,         but       you        will                 not         be         able               to   fix    it                before   you                          purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRescueCenter" target="_blank"><strong>Windows Rescue Center</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrashesDeliverer"><strong>Windows Crashes Deliverer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSaviourFirewall"><strong>Windows Saviour Firewall</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAvertingSystem"><strong>Windows Averting System</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccidentsPrevention"><strong>Windows Accidents Prevention</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver"><strong>Windows Troubles Solver</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Windows Anticrashes Utility</strong></a></li>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong></strong><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsProtectionAlarm_1.png"><img class="alignnone size-medium wp-image-2253" title="Adware.Win32.WindowsProtectionAlarm" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsProtectionAlarm_1-400x208.png" alt="Adware.Win32.WindowsProtectionAlarm" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsProtectionAlarm_2.png"><img class="alignnone size-medium wp-image-2254" title="Adware.Win32.WindowsProtectionAlarm" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsProtectionAlarm_2-400x208.png" alt="Adware.Win32.WindowsProtectionAlarm" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsProtectionAlarm_3.png"><img class="alignnone size-medium wp-image-2255" title="Adware.Win32.WindowsProtectionAlarm" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsProtectionAlarm_3-400x228.png" alt="Adware.Win32.WindowsProtectionAlarm" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsProtectionAlarm_4.png"><img class="alignnone size-medium wp-image-2256" title="Adware.Win32.WindowsProtectionAlarm" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsProtectionAlarm_4-400x228.png" alt="Adware.Win32.WindowsProtectionAlarm" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsProtectionAlarm_5.png"><img class="alignnone size-medium wp-image-2257" title="Adware.Win32.WindowsProtectionAlarm" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsProtectionAlarm_5-400x235.png" alt="Adware.Win32.WindowsProtectionAlarm" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsProtectionAlarm_6.png"><img class="alignnone size-medium wp-image-2258" title="Adware.Win32.WindowsProtectionAlarm" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsProtectionAlarm_6-400x214.png" alt="Adware.Win32.WindowsProtectionAlarm" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsProtectionAlarm_7.png"><img class="alignnone size-medium wp-image-2259" title="Adware.Win32.WindowsProtectionAlarm" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsProtectionAlarm_7-400x214.png" alt="Adware.Win32.WindowsProtectionAlarm" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsProtectionAlarm_8.png"><img class="alignnone size-medium wp-image-2260" title="Adware.Win32.WindowsProtectionAlarm" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsProtectionAlarm_8-400x211.png" alt="Adware.Win32.WindowsProtectionAlarm" width="400" height="211" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsProtectionAlarm_9.png"><img class="alignnone size-medium wp-image-2261" title="Adware.Win32.WindowsProtectionAlarm" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsProtectionAlarm_9-400x325.png" alt="Adware.Win32.WindowsProtectionAlarm" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows Protection Alarm</strong><strong> </strong><strong> </strong><strong>(</strong><strong>A<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionAlarm" target="_blank">dware.Win32.WindowsProtectionAlarm</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/22/windows-av-software-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows AV Software Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/06/10/windows-protection-alarm-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Rescue Center Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/06/04/windows-rescue-center-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/06/04/windows-rescue-center-adware-removal-instructions/#comments</comments>
		<pubDate>Sat, 04 Jun 2011 04:50:39 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Rescue Center]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2240</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Rescue Center adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsRescueCenter. Windows Rescue Center is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Rescue Center </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRescueCenter"><strong>Adware.Win32.</strong><strong>WindowsRescueCenter</strong></a><strong>.</strong></p>
<p><strong>Windows Rescue Center</strong><strong> </strong>is   a                             rogue           application.                                                    A         rogue                 application      tries      to       trick  you   by                                  displaying                            false                              positive/misleading             scan                     results                           report,   which    says                that   your                                             computer        has  a          problem,            or     infected     with                                viruses       or             trojan,         but      you        will                 not         be         able              to   fix    it                before   you                         purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrashesDeliverer"><strong>Windows Crashes Deliverer</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSaviourFirewall"><strong>Windows Saviour Firewall</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAvertingSystem"><strong>Windows Averting System</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccidentsPrevention"><strong>Windows Accidents Prevention</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver"><strong>Windows Troubles Solver</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Windows Anticrashes Utility</strong></a></li>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong></strong><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsRescueCenter_1.png"><img class="alignnone size-medium wp-image-2241" title="Adware.Win32.WindowsRescueCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsRescueCenter_1-400x208.png" alt="Adware.Win32.WindowsRescueCenter" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsRescueCenter_2.png"><img class="alignnone size-medium wp-image-2242" title="Adware.Win32.WindowsRescueCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsRescueCenter_2-400x208.png" alt="Adware.Win32.WindowsRescueCenter" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsRescueCenter_3.png"><img class="alignnone size-medium wp-image-2243" title="Adware.Win32.WindowsRescueCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsRescueCenter_3-400x228.png" alt="Adware.Win32.WindowsRescueCenter" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsRescueCenter_4.png"><img class="alignnone size-medium wp-image-2244" title="Adware.Win32.WindowsRescueCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsRescueCenter_4-400x228.png" alt="Adware.Win32.WindowsRescueCenter" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsRescueCenter_5.png"><img class="alignnone size-medium wp-image-2245" title="Adware.Win32.WindowsRescueCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsRescueCenter_5-400x235.png" alt="Adware.Win32.WindowsRescueCenter" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsRescueCenter_6.png"><img class="alignnone size-medium wp-image-2246" title="Adware.Win32.WindowsRescueCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsRescueCenter_6-400x214.png" alt="Adware.Win32.WindowsRescueCenter" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsRescueCenter_7.png"><img class="alignnone size-medium wp-image-2247" title="Adware.Win32.WindowsRescueCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsRescueCenter_7-400x214.png" alt="Adware.Win32.WindowsRescueCenter" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsRescueCenter_8.png"><img class="alignnone size-medium wp-image-2248" title="Adware.Win32.WindowsRescueCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsRescueCenter_8-400x209.png" alt="Adware.Win32.WindowsRescueCenter" width="400" height="209" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsRescueCenter_9.png"><img class="alignnone size-medium wp-image-2249" title="Adware.Win32.WindowsRescueCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsRescueCenter_9-400x325.png" alt="Adware.Win32.WindowsRescueCenter" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows Rescue Center</strong><strong> </strong><strong> </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRescueCenter"><strong>Adware.Win32.WindowsRescueCenter</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-defence-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Defence Center Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/06/04/windows-rescue-center-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Crashes Deliverer Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/06/04/windows-crashes-deliverer-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/06/04/windows-crashes-deliverer-adware-removal-instructions/#comments</comments>
		<pubDate>Sat, 04 Jun 2011 04:42:57 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Crashes Deliverer]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2231</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Crashes Deliverer adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsCrashesDeliverer. Windows Crashes Deliverer is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Crashes Deliverer </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrashesDeliverer"><strong>Adware.Win32.WindowsCrashesDeliverer</strong></a><strong>.</strong></p>
<p><strong>Windows Crashes Deliverer</strong><strong> </strong>is   a                            rogue           application.                                                   A         rogue                application      tries      to       trick  you   by                                 displaying                            false                             positive/misleading             scan                    results                           report,   which    says               that   your                                             computer       has  a          problem,            or     infected     with                               viruses       or             trojan,         but     you        will                 not         be         able             to   fix    it                before   you                        purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSaviourFirewall"><strong>Windows Saviour Firewall</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAvertingSystem"><strong>Windows Averting System</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccidentsPrevention"><strong>Windows Accidents Prevention</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver"><strong>Windows Troubles Solver</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Windows Anticrashes Utility</strong></a></li>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong></strong><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsCrashesDeliverer_1.png"><img class="alignnone size-medium wp-image-2232" title="Adware.Win32.WindowsCrashesDeliverer" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsCrashesDeliverer_1-400x208.png" alt="Adware.Win32.WindowsCrashesDeliverer" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsCrashesDeliverer_2.png"><img class="alignnone size-medium wp-image-2233" title="Adware.Win32.WindowsCrashesDeliverer" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsCrashesDeliverer_2-400x208.png" alt="Adware.Win32.WindowsCrashesDeliverer" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsCrashesDeliverer_3.png"><img class="alignnone size-medium wp-image-2234" title="Adware.Win32.WindowsCrashesDeliverer" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsCrashesDeliverer_3-400x228.png" alt="Adware.Win32.WindowsCrashesDeliverer" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsCrashesDeliverer_4.png"><img class="alignnone size-medium wp-image-2235" title="Adware.Win32.WindowsCrashesDeliverer" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsCrashesDeliverer_4-400x214.png" alt="Adware.Win32.WindowsCrashesDeliverer" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsCrashesDeliverer_5.png"><img class="alignnone size-medium wp-image-2236" title="Adware.Win32.WindowsCrashesDeliverer" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsCrashesDeliverer_5-400x214.png" alt="Adware.Win32.WindowsCrashesDeliverer" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsCrashesDeliverer_6.png"><img class="alignnone size-medium wp-image-2237" title="Adware.Win32.WindowsCrashesDeliverer" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsCrashesDeliverer_6-400x209.png" alt="Adware.Win32.WindowsCrashesDeliverer" width="400" height="209" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsCrashesDeliverer_7.png"><img class="alignnone size-medium wp-image-2238" title="Adware.Win32.WindowsCrashesDeliverer" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsCrashesDeliverer_7-400x325.png" alt="Adware.Win32.WindowsCrashesDeliverer" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows Crashes Deliverer</strong><strong> </strong><strong> </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrashesDeliverer"><strong>Adware.Win32.WindowsSaviourFirewall</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/05/27/windows-firewall-unit-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Firewall Unit Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/06/04/windows-crashes-deliverer-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Saviour Firewall Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/06/04/windows-saviour-firewall-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/06/04/windows-saviour-firewall-adware-removal-instructions/#comments</comments>
		<pubDate>Sat, 04 Jun 2011 04:34:32 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Saviour Firewall]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2220</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Saviour Firewall adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsSaviourFirewall. Windows Saviour Firewall is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Saviour Firewall </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSaviourFirewall"><strong>Adware.Win32.WindowsSaviourFirewall</strong></a><strong>.</strong></p>
<p><strong>Windows Saviour Firewall</strong><strong> </strong>is   a                           rogue           application.                                                  A         rogue                application     tries      to       trick  you   by                                displaying                            false                            positive/misleading             scan                    results                          report,   which    says               that   your                                            computer       has  a         problem,            or     infected     with                              viruses       or             trojan,         but     you        will                not         be         able             to   fix    it               before   you                        purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAvertingSystem"><strong>Windows Averting System</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccidentsPrevention"><strong>Windows Accidents Prevention</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver"><strong>Windows Troubles Solver</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Windows Anticrashes Utility</strong></a></li>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong></strong><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsSaviourFirewall_1.png"><img class="alignnone size-medium wp-image-2221" title="Adware.Win32.WindowsSaviourFirewall" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsSaviourFirewall_1-400x208.png" alt="Adware.Win32.WindowsSaviourFirewall" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsSaviourFirewall_2.png"><img class="alignnone size-medium wp-image-2222" title="Adware.Win32.WindowsSaviourFirewall" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsSaviourFirewall_2-400x208.png" alt="Adware.Win32.WindowsSaviourFirewall" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsSaviourFirewall_3.png"><img class="alignnone size-medium wp-image-2223" title="Adware.Win32.WindowsSaviourFirewall" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsSaviourFirewall_3-400x228.png" alt="Adware.Win32.WindowsSaviourFirewall" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsSaviourFirewall_4.png"><img class="alignnone size-medium wp-image-2224" title="Adware.Win32.WindowsSaviourFirewall" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsSaviourFirewall_4-400x228.png" alt="Adware.Win32.WindowsSaviourFirewall" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsSaviourFirewall_5.png"><img class="alignnone size-medium wp-image-2225" title="Adware.Win32.WindowsSaviourFirewall" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsSaviourFirewall_5-400x235.png" alt="Adware.Win32.WindowsSaviourFirewall" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsSaviourFirewall_6.png"><img class="alignnone size-medium wp-image-2226" title="Adware.Win32.WindowsSaviourFirewall" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsSaviourFirewall_6-400x214.png" alt="Adware.Win32.WindowsSaviourFirewall" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsSaviourFirewall_7.png"><img class="alignnone size-medium wp-image-2227" title="Adware.Win32.WindowsSaviourFirewall" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsSaviourFirewall_7-400x214.png" alt="Adware.Win32.WindowsSaviourFirewall" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsSaviourFirewall_8.png"><img class="alignnone size-medium wp-image-2228" title="Adware.Win32.WindowsSaviourFirewall" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsSaviourFirewall_8-400x209.png" alt="Adware.Win32.WindowsSaviourFirewall" width="400" height="209" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsSaviourFirewall_9.png"><img class="alignnone size-medium wp-image-2229" title="Adware.Win32.WindowsSaviourFirewall" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsSaviourFirewall_9-400x325.png" alt="Adware.Win32.WindowsSaviourFirewall" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows Saviour Firewall</strong><strong> </strong><strong> </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSaviourFirewall"><strong>Adware.Win32.WindowsSaviourFirewall</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/06/04/windows-crashes-deliverer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Crashes Deliverer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/05/27/windows-firewall-unit-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Firewall Unit Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/06/04/windows-saviour-firewall-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Averting System Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/06/04/windows-averting-system-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/06/04/windows-averting-system-adware-removal-instructions/#comments</comments>
		<pubDate>Sat, 04 Jun 2011 04:25:41 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Averting System]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2210</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Averting System adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsAvertingSystem. Windows Averting System is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Averting System </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAvertingSystem"><strong>Adware.Win32.WindowsAvertingSystem</strong></a><strong>.</strong></p>
<p><strong>Windows Averting System</strong><strong> </strong>is   a                          rogue           application.                                                 A         rogue                application    tries      to       trick  you   by                               displaying                            false                           positive/misleading             scan                    results                         report,   which    says               that   your                                           computer       has  a        problem,            or     infected     with                             viruses       or             trojan,         but     you        will               not         be         able             to   fix    it              before   you                        purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccidentsPrevention"><strong>Windows Accidents Prevention</strong><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver"><strong>Windows Troubles Solver</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Windows Anticrashes Utility</strong></a></li>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong></strong><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAvertingSystem_1.png"><img class="alignnone size-medium wp-image-2211" title="Adware.Win32.WindowsAvertingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAvertingSystem_1-400x208.png" alt="Adware.Win32.WindowsAvertingSystem" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAvertingSystem_2.png"><img class="alignnone size-medium wp-image-2212" title="Adware.Win32.WindowsAvertingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAvertingSystem_2-400x228.png" alt="Adware.Win32.WindowsAvertingSystem" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAvertingSystem_3.png"><img class="alignnone size-medium wp-image-2213" title="Adware.Win32.WindowsAvertingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAvertingSystem_3-400x228.png" alt="Adware.Win32.WindowsAvertingSystem" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAvertingSystem_4.png"><img class="alignnone size-medium wp-image-2214" title="Adware.Win32.WindowsAvertingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAvertingSystem_4-400x235.png" alt="Adware.Win32.WindowsAvertingSystem" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAvertingSystem_5.png"><img class="alignnone size-medium wp-image-2215" title="Adware.Win32.WindowsAvertingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAvertingSystem_5-400x214.png" alt="Adware.Win32.WindowsAvertingSystem" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAvertingSystem_6.png"><img class="alignnone size-medium wp-image-2216" title="Adware.Win32.WindowsAvertingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAvertingSystem_6-400x214.png" alt="Adware.Win32.WindowsAvertingSystem" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAvertingSystem_7.png"><img class="alignnone size-medium wp-image-2217" title="Adware.Win32.WindowsAvertingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAvertingSystem_7-400x209.png" alt="Adware.Win32.WindowsAvertingSystem" width="400" height="209" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAvertingSystem_8.png"><img class="alignnone size-medium wp-image-2218" title="Adware.Win32.WindowsAvertingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAvertingSystem_8-400x325.png" alt="Adware.Win32.WindowsAvertingSystem" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows Averting System</strong><strong> </strong><strong> </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAvertingSystem"><strong>Adware.Win32.WindowsAvertingSystem</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/06/04/windows-crashes-deliverer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Crashes Deliverer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/06/04/windows-averting-system-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Accidents Prevention Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/06/04/windows-accidents-prevention-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/06/04/windows-accidents-prevention-adware-removal-instructions/#comments</comments>
		<pubDate>Sat, 04 Jun 2011 04:14:13 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Accidents Prevention]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2198</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Troubles Solver adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsAccidentsPrevention. Windows Accidents Prevention is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Troubles Solver </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccidentsPrevention"><strong>Adware.Win32.WindowsAccidentsPrevention</strong></a><strong>.</strong></p>
<p><strong>Windows Accidents Prevention</strong><strong> </strong>is   a                         rogue           application.                                                A         rogue                application   tries      to       trick  you   by                              displaying                            false                          positive/misleading             scan                    results                        report,   which    says               that   your                                          computer       has  a        problem,           or     infected     with                             viruses      or             trojan,         but     you        will              not         be         able             to   fix    it             before   you                        purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver"><strong>Windows Troubles Solver</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Windows Anticrashes Utility</strong></a></li>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong></strong><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAccidentsPrevention_1.png"><img class="alignnone size-medium wp-image-2199" title="Adware.Win32.WindowsAccidentsPrevention" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAccidentsPrevention_1-400x208.png" alt="Adware.Win32.WindowsAccidentsPrevention" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAccidentsPrevention_2.png"><img class="alignnone size-medium wp-image-2200" title="Adware.Win32.WindowsAccidentsPrevention" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAccidentsPrevention_2-400x208.png" alt="Adware.Win32.WindowsAccidentsPrevention" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAccidentsPrevention_3.png"><img class="alignnone size-medium wp-image-2201" title="Adware.Win32.WindowsAccidentsPrevention" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAccidentsPrevention_3-400x228.png" alt="Adware.Win32.WindowsAccidentsPrevention" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAccidentsPrevention_4.png"><img class="alignnone size-medium wp-image-2202" title="Adware.Win32.WindowsAccidentsPrevention" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAccidentsPrevention_4-400x235.png" alt="Adware.Win32.WindowsAccidentsPrevention" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAccidentsPrevention_5.png"><img class="alignnone size-medium wp-image-2203" title="Adware.Win32.WindowsAccidentsPrevention" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAccidentsPrevention_5-400x214.png" alt="Adware.Win32.WindowsAccidentsPrevention" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAccidentsPrevention_6.png"><img class="alignnone size-medium wp-image-2204" title="Adware.Win32.WindowsAccidentsPrevention" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAccidentsPrevention_6-400x214.png" alt="Adware.Win32.WindowsAccidentsPrevention" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAccidentsPrevention_7.png"><img class="alignnone size-medium wp-image-2205" title="Adware.Win32.WindowsAccidentsPrevention" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAccidentsPrevention_7-400x211.png" alt="Adware.Win32.WindowsAccidentsPrevention" width="400" height="211" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAccidentsPrevention_8.png"><img class="alignnone size-medium wp-image-2206" title="Adware.Win32.WindowsAccidentsPrevention" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAccidentsPrevention_8-400x325.png" alt="Adware.Win32.WindowsAccidentsPrevention" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows Accidents Prevention</strong><strong> </strong><strong> </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAccidentsPrevention" target="_blank"><strong>Adware.Win32.WindowsAccidentsPrevention</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/06/04/windows-averting-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Averting System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/06/04/windows-accidents-prevention-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Troubles Solver Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/06/02/windows-troubles-solver-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/06/02/windows-troubles-solver-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 02 Jun 2011 11:08:01 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Troubles Solver]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2187</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Troubles Solver adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsTroublesSolver. Windows Troubles Solver is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Troubles Solver </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver"><strong>Adware.Win32.WindowsTroublesSolver</strong></a><strong>.</strong></p>
<p><strong>Windows Troubles Solver</strong><strong> </strong>is   a                        rogue           application.                                               A         rogue                application   tries     to       trick  you   by                              displaying                           false                         positive/misleading             scan                    results                       report,   which    says               that   your                                         computer       has  a        problem,          or     infected     with                             viruses     or             trojan,         but     you        will              not        be         able             to   fix    it             before  you                        purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Windows Anticrashes Utility</strong></a></li>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong></strong><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesSolver_1.png"><img class="alignnone size-medium wp-image-2188" title="Adware.Win32.WindowsTroublesSolver" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesSolver_1-400x208.png" alt="Adware.Win32.WindowsTroublesSolver" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesSolver_2.png"><img class="alignnone size-medium wp-image-2189" title="Adware.Win32.WindowsTroublesSolver" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesSolver_2-400x208.png" alt="Adware.Win32.WindowsTroublesSolver" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesSolver_3.png"><img class="alignnone size-medium wp-image-2190" title="Adware.Win32.WindowsTroublesSolver" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesSolver_3-400x228.png" alt="Adware.Win32.WindowsTroublesSolver" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesSolver_4.png"><img class="alignnone size-medium wp-image-2191" title="Adware.Win32.WindowsTroublesSolver" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesSolver_4-400x228.png" alt="Adware.Win32.WindowsTroublesSolver" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesSolver_5.png"><img class="alignnone size-medium wp-image-2192" title="Adware.Win32.WindowsTroublesSolver" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesSolver_5-400x235.png" alt="Adware.Win32.WindowsTroublesSolver" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesSolver_6.png"><img class="alignnone size-medium wp-image-2193" title="Adware.Win32.WindowsTroublesSolver" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesSolver_6-400x214.png" alt="Adware.Win32.WindowsTroublesSolver" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesSolver_7.png"><img class="alignnone size-medium wp-image-2194" title="Adware.Win32.WindowsTroublesSolver" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesSolver_7-400x214.png" alt="Adware.Win32.WindowsTroublesSolver" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesSolver_8.png"><img class="alignnone size-medium wp-image-2195" title="Adware.Win32.WindowsTroublesSolver" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesSolver_8-400x211.png" alt="Adware.Win32.WindowsTroublesSolver" width="400" height="211" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesSolver_9.png"><img class="alignnone size-medium wp-image-2196" title="Adware.Win32.WindowsTroublesSolver" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsTroublesSolver_9-400x325.png" alt="Adware.Win32.WindowsTroublesSolver" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows Troubles Solver</strong><strong> </strong><strong> </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesSolver" target="_blank"><strong>Adware.Win32.WindowsTroublesSolver</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/06/04/windows-accidents-prevention-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Accidents Prevention Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/06/02/windows-troubles-solver-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Anticrashes Utility Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/06/02/windows-anticrashes-utility-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/06/02/windows-anticrashes-utility-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 02 Jun 2011 09:15:14 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Anticrashes Utility]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2176</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Anticrashes Utility adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsAnticrashesUtility. Windows Anticrashes Utility is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Anticrashes Utility </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Adware.Win32.WindowsAnticrashesUtility</strong></a><strong>.</strong></p>
<p><strong>Windows Anticrashes Utility</strong><strong> </strong>is   a                       rogue           application.                                              A         rogue                application  tries     to       trick  you   by                             displaying                           false                        positive/misleading             scan                    results                      report,   which    says               that   your                                        computer       has  a        problem,         or     infected     with                             viruses     or            trojan,         but     you        will              not       be         able             to   fix    it             before  you                       purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong>Windows Risks Preventions</strong></a></li>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAnticrashesUtility_1.png"><img class="alignnone size-medium wp-image-2178" title="Adware.Win32.WindowsAnticrashesUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAnticrashesUtility_1-400x208.png" alt="Adware.Win32.WindowsAnticrashesUtility" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAnticrashesUtility_2.png"><img class="alignnone size-medium wp-image-2179" title="Adware.Win32.WindowsAnticrashesUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAnticrashesUtility_2-400x208.png" alt="Adware.Win32.WindowsAnticrashesUtility" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAnticrashesUtility_3.png"><img class="alignnone size-medium wp-image-2180" title="Adware.Win32.WindowsAnticrashesUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAnticrashesUtility_3-400x228.png" alt="Adware.Win32.WindowsAnticrashesUtility" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAnticrashesUtility_4.png"><img class="alignnone size-medium wp-image-2181" title="Adware.Win32.WindowsAnticrashesUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAnticrashesUtility_4-400x235.png" alt="Adware.Win32.WindowsAnticrashesUtility" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAnticrashesUtility_5.png"><img class="alignnone size-medium wp-image-2182" title="Adware.Win32.WindowsAnticrashesUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAnticrashesUtility_5-400x214.png" alt="Adware.Win32.WindowsAnticrashesUtility" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAnticrashesUtility_6.png"><img class="alignnone size-medium wp-image-2183" title="Adware.Win32.WindowsAnticrashesUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAnticrashesUtility_6-400x214.png" alt="Adware.Win32.WindowsAnticrashesUtility" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAnticrashesUtility_7.png"><img class="alignnone size-medium wp-image-2184" title="Adware.Win32.WindowsAnticrashesUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAnticrashesUtility_7-400x211.png" alt="Adware.Win32.WindowsAnticrashesUtility" width="400" height="211" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAnticrashesUtility_8.png"><img class="alignnone size-medium wp-image-2185" title="Adware.Win32.WindowsAnticrashesUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/06/Adware.Win32.WindowsAnticrashesUtility_8-400x325.png" alt="Adware.Win32.WindowsAnticrashesUtility" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows Anticrashes Utility</strong><strong> </strong><strong> </strong><strong>(</strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAnticrashesUtility" target="_blank"><strong>Adware.Win32.WindowsAnticrashesUtility</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/05/27/windows-firewall-unit-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Firewall Unit Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/06/02/windows-troubles-solver-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Solver Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/06/02/windows-anticrashes-utility-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Risks Preventions Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/05/28/windows-risks-preventions-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/05/28/windows-risks-preventions-adware-removal-instructions/#comments</comments>
		<pubDate>Sat, 28 May 2011 06:16:25 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Risks Preventions]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2163</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Risks Preventions adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsRisksPreventions. Windows Risks Preventions is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Risks Preventions </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong>Adware.Win32.WindowsRisksPreventions</strong></a><strong>.</strong></p>
<p><strong>Windows Risks Preventions</strong><strong> </strong>is   a                      rogue           application.                                             A         rogue                application  tries    to       trick  you   by                             displaying                          false                        positive/misleading            scan                    results                      report,  which    says               that   your                                       computer       has  a        problem,         or     infected    with                             viruses     or            trojan,        but     you        will              not       be         able            to   fix    it             before  you                      purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings"><strong>Windows Custom Settings</strong></a></li>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRisksPreventions_1.png"><img class="alignnone size-medium wp-image-2164" title="Adware.Win32.WindowsRisksPreventions" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRisksPreventions_1-400x208.png" alt="Adware.Win32.WindowsRisksPreventions" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRisksPreventions_2.png"><img class="alignnone size-medium wp-image-2165" title="Adware.Win32.WindowsRisksPreventions" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRisksPreventions_2-400x208.png" alt="Adware.Win32.WindowsRisksPreventions" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRisksPreventions_3.png"><img class="alignnone size-medium wp-image-2166" title="Adware.Win32.WindowsRisksPreventions" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRisksPreventions_3-400x228.png" alt="Adware.Win32.WindowsRisksPreventions" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRisksPreventions_4.png"><img class="alignnone size-medium wp-image-2167" title="Adware.Win32.WindowsRisksPreventions" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRisksPreventions_4-400x228.png" alt="Adware.Win32.WindowsRisksPreventions" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRisksPreventions_5.png"><img class="alignnone size-medium wp-image-2168" title="Adware.Win32.WindowsRisksPreventions" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRisksPreventions_5-400x235.png" alt="Adware.Win32.WindowsRisksPreventions" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRisksPreventions_6.png"><img class="alignnone size-medium wp-image-2169" title="Adware.Win32.WindowsRisksPreventions" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRisksPreventions_6-400x214.png" alt="Adware.Win32.WindowsRisksPreventions" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRisksPreventions_7.png"><img class="alignnone size-medium wp-image-2170" title="Adware.Win32.WindowsRisksPreventions" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRisksPreventions_7-400x214.png" alt="Adware.Win32.WindowsRisksPreventions" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRisksPreventions_8.png"><img class="alignnone size-medium wp-image-2171" title="Adware.Win32.WindowsRisksPreventions" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRisksPreventions_8-400x211.png" alt="Adware.Win32.WindowsRisksPreventions" width="400" height="211" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRisksPreventions_9.png"><img class="alignnone size-medium wp-image-2172" title="Adware.Win32.WindowsRisksPreventions" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRisksPreventions_9-400x325.png" alt="Adware.Win32.WindowsRisksPreventions" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows Risks Preventions</strong><strong> </strong><strong> </strong><strong>(</strong><a title="Windows Risks Preventions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRisksPreventions" target="_blank"><strong>Adware.Win32.WindowsRisksPreventions</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/06/02/windows-anticrashes-utility-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Anticrashes Utility Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/06/02/windows-troubles-solver-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Solver Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/06/04/windows-averting-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Averting System Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/05/28/windows-risks-preventions-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Custom Settings Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/05/28/windows-custom-settings-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/05/28/windows-custom-settings-adware-removal-instructions/#comments</comments>
		<pubDate>Sat, 28 May 2011 06:09:15 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Custom Settings]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2150</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Custom Settings adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsCustomSettings. Windows Custom Settings is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Custom Settings </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings" target="_blank"><strong>Adware.Win32.WindowsCustomSettings</strong></a><strong>.</strong></p>
<p><strong>Windows Custom</strong><strong> Settings </strong>is   a                     rogue           application.                                            A         rogue                application  tries    to      trick  you   by                             displaying                         false                        positive/misleading           scan                    results                      report,  which   says               that   your                                      computer       has  a        problem,         or     infected    with                            viruses     or            trojan,        but    you        will              not       be         able            to  fix    it             before  you                      purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Windows Firewall Unit</strong></a></li>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsCustomSettings_1.png"><img class="alignnone size-medium wp-image-2151" title="Adware.Win32.WindowsCustomSettings" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsCustomSettings_1-400x208.png" alt="Adware.Win32.WindowsCustomSettings" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsCustomSettings_2.png"><img class="alignnone size-medium wp-image-2152" title="Adware.Win32.WindowsCustomSettings" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsCustomSettings_2-400x208.png" alt="Adware.Win32.WindowsCustomSettings" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsCustomSettings_3.png"><img class="alignnone size-medium wp-image-2153" title="Adware.Win32.WindowsCustomSettings" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsCustomSettings_3-400x228.png" alt="Adware.Win32.WindowsCustomSettings" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsCustomSettings_4.png"><img class="alignnone size-medium wp-image-2154" title="Adware.Win32.WindowsCustomSettings" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsCustomSettings_4-400x228.png" alt="Adware.Win32.WindowsCustomSettings" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsCustomSettings_5.png"><img class="alignnone size-medium wp-image-2155" title="Adware.Win32.WindowsCustomSettings" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsCustomSettings_5-400x235.png" alt="Adware.Win32.WindowsCustomSettings" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsCustomSettings_6.png"><img class="alignnone size-medium wp-image-2156" title="Adware.Win32.WindowsCustomSettings" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsCustomSettings_6-400x214.png" alt="Adware.Win32.WindowsCustomSettings" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsCustomSettings_7.png"><img class="alignnone size-medium wp-image-2157" title="Adware.Win32.WindowsCustomSettings" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsCustomSettings_7-400x214.png" alt="Adware.Win32.WindowsCustomSettings" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsCustomSettings_8.png"><img class="alignnone size-medium wp-image-2158" title="Adware.Win32.WindowsCustomSettings" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsCustomSettings_8-400x211.png" alt="Adware.Win32.WindowsCustomSettings" width="400" height="211" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsCustomSettings_9.png"><img class="alignnone size-medium wp-image-2159" title="Adware.Win32.WindowsCustomSettings" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsCustomSettings_9-400x325.png" alt="Adware.Win32.WindowsCustomSettings" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows Custom Settings</strong><strong> </strong><strong> </strong><strong>(</strong><a title="Windows Custom Settings" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustomSettings" target="_blank"><strong>Adware.Win32.WindowsCustomSettings</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/06/02/windows-anticrashes-utility-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Anticrashes Utility Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/05/28/windows-custom-settings-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Firewall Unit Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/05/27/windows-firewall-unit-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/05/27/windows-firewall-unit-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 27 May 2011 14:39:06 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Firewall Unit]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2141</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Firewall Unit adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsFirewallUnit. Windows Firewall Unit is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Firewall Unit </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Adware.Win32.WindowsFirewallUnit</strong></a><strong>.</strong></p>
<p><strong>Windows Firewall Unit</strong><strong> </strong>is   a                    rogue           application.                                           A         rogue                application  tries    to     trick  you   by                             displaying                        false                        positive/misleading           scan                   results                      report,  which   says              that   your                                      computer      has  a        problem,         or     infected    with                           viruses     or            trojan,        but    you        will             not       be         able            to  fix    it            before  you                      purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Windows Safeguard Utility</strong></a></li>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsFirewallUnit_1.png"><img class="alignnone size-medium wp-image-2142" title="Adware.Win32.WindowsFirewallUnit" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsFirewallUnit_1-400x208.png" alt="Adware.Win32.WindowsFirewallUnit" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsFirewallUnit_2.png"><img class="alignnone size-medium wp-image-2143" title="Adware.Win32.WindowsFirewallUnit" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsFirewallUnit_2-400x208.png" alt="Adware.Win32.WindowsFirewallUnit" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsFirewallUnit_3.png"><img class="alignnone size-medium wp-image-2144" title="Adware.Win32.WindowsFirewallUnit" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsFirewallUnit_3-400x228.png" alt="Adware.Win32.WindowsFirewallUnit" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsFirewallUnit_4.png"><img class="alignnone size-medium wp-image-2145" title="Adware.Win32.WindowsFirewallUnit" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsFirewallUnit_4-400x228.png" alt="Adware.Win32.WindowsFirewallUnit" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsFirewallUnit_5.png"><img class="alignnone size-medium wp-image-2146" title="Adware.Win32.WindowsFirewallUnit" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsFirewallUnit_5-400x214.png" alt="Adware.Win32.WindowsFirewallUnit" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsFirewallUnit_6.png"><img class="alignnone size-medium wp-image-2147" title="Adware.Win32.WindowsFirewallUnit" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsFirewallUnit_6-400x211.png" alt="Adware.Win32.WindowsFirewallUnit" width="400" height="211" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsFirewallUnit_7.png"><img class="alignnone size-medium wp-image-2148" title="Adware.Win32.WindowsFirewallUnit" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsFirewallUnit_7-400x325.png" alt="Adware.Win32.WindowsFirewallUnit" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows Firewall Unit</strong><strong> </strong><strong> </strong><strong>(</strong><a title="Windows Firewall Unit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallUnit" target="_blank"><strong>Adware.Win32.WindowsFirewallUnit</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/05/28/windows-custom-settings-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Custom Settings Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/06/02/windows-anticrashes-utility-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Anticrashes Utility Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/05/27/windows-firewall-unit-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Safeguard Utility Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/05/24/windows-safeguard-utility-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/05/24/windows-safeguard-utility-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 24 May 2011 09:35:33 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Safeguard Utility]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2129</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Safeguard Utility adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsSafeguardUtility. Windows Safeguard Utility is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Safeguard Utility </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Adware.Win32.WindowsSafeguardUtility</strong></a><strong>.</strong></p>
<p><strong>Windows Safeguard Utility</strong><strong> </strong>is   a                   rogue           application.                                          A         rogue                application  tries    to    trick  you   by                             displaying                       false                        positive/misleading           scan                  results                      report,  which   says             that   your                                      computer      has a        problem,         or     infected    with                          viruses     or            trojan,        but    you        will            not       be         able            to  fix    it           before  you                      purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Windows Repairing System</strong></a></li>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSafeguardUtility_1.png"><img class="alignnone size-medium wp-image-2130" title="Adware.Win32.WindowsSafeguardUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSafeguardUtility_1-400x208.png" alt="Adware.Win32.WindowsSafeguardUtility" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSafeguardUtility_2.png"><img class="alignnone size-medium wp-image-2131" title="Adware.Win32.WindowsSafeguardUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSafeguardUtility_2-400x208.png" alt="Adware.Win32.WindowsSafeguardUtility" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSafeguardUtility_3.png"><img class="alignnone size-medium wp-image-2132" title="Adware.Win32.WindowsSafeguardUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSafeguardUtility_3-400x228.png" alt="Adware.Win32.WindowsSafeguardUtility" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSafeguardUtility_4.png"><img class="alignnone size-medium wp-image-2133" title="Adware.Win32.WindowsSafeguardUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSafeguardUtility_4-400x228.png" alt="Adware.Win32.WindowsSafeguardUtility" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSafeguardUtility_5.png"><img class="alignnone size-medium wp-image-2134" title="Adware.Win32.WindowsSafeguardUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSafeguardUtility_5-400x235.png" alt="Adware.Win32.WindowsSafeguardUtility" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSafeguardUtility_6.png"><img class="alignnone size-medium wp-image-2135" title="Adware.Win32.WindowsSafeguardUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSafeguardUtility_6-400x214.png" alt="Adware.Win32.WindowsSafeguardUtility" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSafeguardUtility_7.png"><img class="alignnone size-medium wp-image-2136" title="Adware.Win32.WindowsSafeguardUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSafeguardUtility_7-400x214.png" alt="Adware.Win32.WindowsSafeguardUtility" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSafeguardUtility_8.png"><img class="alignnone size-medium wp-image-2137" title="Adware.Win32.WindowsSafeguardUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSafeguardUtility_8-400x211.png" alt="Adware.Win32.WindowsSafeguardUtility" width="400" height="211" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSafeguardUtility_9.png"><img class="alignnone size-medium wp-image-2138" title="Adware.Win32.WindowsSafeguardUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSafeguardUtility_9-400x325.png" alt="Adware.Win32.WindowsSafeguardUtility" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows Safeguard Utility</strong><strong> </strong><strong> </strong><strong>(</strong><a title="Windows Safeguard Utility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUtility" target="_blank"><strong>Adware.Win32.WindowsSafeguardUtility</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/05/27/windows-firewall-unit-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Firewall Unit Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/05/28/windows-custom-settings-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Custom Settings Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/05/24/windows-safeguard-utility-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Repairing System Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/05/24/windows-repairing-system-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/05/24/windows-repairing-system-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 24 May 2011 08:06:21 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Repairing System]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2117</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Repairing System adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsRepairingSystem. Windows Repairing System is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Repairing System </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Adware.Win32.WindowsRepairingSystem</strong></a><strong>.</strong></p>
<p><strong>Windows Repairing System</strong><strong> </strong>is   a                  rogue           application.                                         A         rogue                application  tries    to   trick  you   by                             displaying                      false                        positive/misleading           scan                 results                      report,  which   says            that   your                                      computer      has a       problem,         or     infected    with                         viruses     or            trojan,        but    you        will           not       be         able            to  fix    it           before you                      purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Windows Precautions Center</strong></a></li>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRepairingSystem_1.png"><img class="alignnone size-medium wp-image-2118" title="Adware.Win32.WindowsRepairingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRepairingSystem_1-400x208.png" alt="Adware.Win32.WindowsRepairingSystem" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRepairingSystem_2.png"><img class="alignnone size-medium wp-image-2119" title="Adware.Win32.WindowsRepairingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRepairingSystem_2-400x208.png" alt="Adware.Win32.WindowsRepairingSystem" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRepairingSystem_3.png"><img class="alignnone size-medium wp-image-2120" title="Adware.Win32.WindowsRepairingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRepairingSystem_3-400x228.png" alt="Adware.Win32.WindowsRepairingSystem" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRepairingSystem_4.png"><img class="alignnone size-medium wp-image-2121" title="Adware.Win32.WindowsRepairingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRepairingSystem_4-400x228.png" alt="Adware.Win32.WindowsRepairingSystem" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRepairingSystem_5.png"><img class="alignnone size-medium wp-image-2122" title="Adware.Win32.WindowsRepairingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRepairingSystem_5-400x235.png" alt="Adware.Win32.WindowsRepairingSystem" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRepairingSystem_6.png"><img class="alignnone size-medium wp-image-2123" title="Adware.Win32.WindowsRepairingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRepairingSystem_6-400x214.png" alt="Adware.Win32.WindowsRepairingSystem" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRepairingSystem_7.png"><img class="alignnone size-medium wp-image-2124" title="Adware.Win32.WindowsRepairingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRepairingSystem_7-400x214.png" alt="Adware.Win32.WindowsRepairingSystem" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRepairingSystem_8.png"><img class="alignnone size-medium wp-image-2125" title="Adware.Win32.WindowsRepairingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRepairingSystem_8-400x211.png" alt="Adware.Win32.WindowsRepairingSystem" width="400" height="211" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRepairingSystem_9.png"><img class="alignnone size-medium wp-image-2126" title="Adware.Win32.WindowsRepairingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsRepairingSystem_9-400x325.png" alt="Adware.Win32.WindowsRepairingSystem" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows Repairing System</strong><strong> </strong><strong> </strong><strong>(</strong><a title="Windows Repairing System" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepairingSystem" target="_blank"><strong>Adware.Win32.WindowsRepairingSystem</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/05/27/windows-firewall-unit-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Firewall Unit Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/05/24/windows-safeguard-utility-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Safeguard Utility Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/19/windows-emergency-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Emergency System Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/05/24/windows-repairing-system-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Precautions Center Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/05/24/windows-precautions-center-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/05/24/windows-precautions-center-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 24 May 2011 07:50:12 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Precautions Center]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2106</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Precautions Center adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsPrecautionsCenter. Windows Precautions Center is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Precautions Center </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Adware.Win32.WindowsPrecautionsCenter</strong></a><strong>.</strong></p>
<p><strong>Windows Precautions Center</strong><strong> </strong>is   a                 rogue           application.                                        A         rogue                application  tries    to  trick  you   by                             displaying                     false                        positive/misleading           scan                results                      report,  which   says           that   your                                      computer      has a      problem,         or     infected    with                        viruses     or            trojan,        but    you        will          not       be         able            to  fix    it           before you                     purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Windows System Tasks</strong></a></li>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a></strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a><strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong></li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsPrecautionsCenter_1.png"><img class="alignnone size-medium wp-image-2107" title="Adware.Win32.WindowsPrecautionsCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsPrecautionsCenter_1-400x208.png" alt="Adware.Win32.WindowsPrecautionsCenter" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsPrecautionsCenter_2.png"><img class="alignnone size-medium wp-image-2108" title="Adware.Win32.WindowsPrecautionsCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsPrecautionsCenter_2-400x208.png" alt="Adware.Win32.WindowsPrecautionsCenter" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsPrecautionsCenter_3.png"><img class="alignnone size-medium wp-image-2109" title="Adware.Win32.WindowsPrecautionsCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsPrecautionsCenter_3-400x228.png" alt="Adware.Win32.WindowsPrecautionsCenter" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsPrecautionsCenter_4.png"><img class="alignnone size-medium wp-image-2110" title="Adware.Win32.WindowsPrecautionsCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsPrecautionsCenter_4-400x228.png" alt="Adware.Win32.WindowsPrecautionsCenter" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsPrecautionsCenter_5.png"><img class="alignnone size-medium wp-image-2111" title="Adware.Win32.WindowsPrecautionsCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsPrecautionsCenter_5-400x235.png" alt="Adware.Win32.WindowsPrecautionsCenter" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsPrecautionsCenter_6.png"><img class="alignnone size-medium wp-image-2112" title="Adware.Win32.WindowsPrecautionsCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsPrecautionsCenter_6-400x214.png" alt="Adware.Win32.WindowsPrecautionsCenter" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsPrecautionsCenter_7.png"><img class="alignnone size-medium wp-image-2113" title="Adware.Win32.WindowsPrecautionsCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsPrecautionsCenter_7-400x214.png" alt="Adware.Win32.WindowsPrecautionsCenter" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsPrecautionsCenter_8.png"><img class="alignnone size-medium wp-image-2114" title="Adware.Win32.WindowsPrecautionsCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsPrecautionsCenter_8-400x211.png" alt="Adware.Win32.WindowsPrecautionsCenter" width="400" height="211" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsPrecautionsCenter_9.png"><img class="alignnone size-medium wp-image-2115" title="Adware.Win32.WindowsPrecautionsCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsPrecautionsCenter_9-400x325.png" alt="Adware.Win32.WindowsPrecautionsCenter" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows Precautions Center</strong><strong> </strong><strong> </strong><strong>(</strong><a title="Windows Precautions Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPrecautionsCenter" target="_blank"><strong>Adware.Win32.WindowsPrecautionsCenter</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/05/24/windows-repairing-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Repairing System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-defence-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Defence Center Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/05/24/windows-precautions-center-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows System Tasks Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/05/20/windows-system-tasks-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/05/20/windows-system-tasks-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 20 May 2011 07:22:30 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows System Tasks]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2093</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows System Tasks adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsSystemTasks. Windows System Tasks is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows System Tasks </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Adware.Win32.WindowsSystemTasks</strong></a><strong>.</strong></p>
<p><strong>Windows System Tasks</strong><strong> </strong>is   a                rogue           application.                                       A         rogue                application  tries    to  trick  you  by                             displaying                     false                       positive/misleading           scan               results                      report,  which   says           that   your                                     computer      has a      problem,        or     infected    with                        viruses     or           trojan,        but    you        will          not       be        able            to  fix    it           before you                    purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Windows Protection Servant</strong></a></li>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a>,</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong>.</li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSystemTasks_1.png"><img class="alignnone size-medium wp-image-2095" title="Adware.Win32.WindowsSystemTasks" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSystemTasks_1-400x208.png" alt="Adware.Win32.WindowsSystemTasks" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSystemTasks_2.png"><img class="alignnone size-medium wp-image-2096" title="Adware.Win32.WindowsSystemTasks" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSystemTasks_2-400x208.png" alt="Adware.Win32.WindowsSystemTasks" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSystemTasks_3.png"><img class="alignnone size-medium wp-image-2097" title="Adware.Win32.WindowsSystemTasks" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSystemTasks_3-400x228.png" alt="Adware.Win32.WindowsSystemTasks" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSystemTasks_4.png"><img class="alignnone size-medium wp-image-2098" title="Adware.Win32.WindowsSystemTasks" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSystemTasks_4-400x228.png" alt="Adware.Win32.WindowsSystemTasks" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSystemTasks_5.png"><img class="alignnone size-medium wp-image-2099" title="Adware.Win32.WindowsSystemTasks" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSystemTasks_5-400x235.png" alt="Adware.Win32.WindowsSystemTasks" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSystemTasks_6.png"><img class="alignnone size-medium wp-image-2100" title="Adware.Win32.WindowsSystemTasks" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSystemTasks_6-400x214.png" alt="Adware.Win32.WindowsSystemTasks" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSystemTasks_7.png"><img class="alignnone size-medium wp-image-2101" title="Adware.Win32.WindowsSystemTasks" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSystemTasks_7-400x214.png" alt="Adware.Win32.WindowsSystemTasks" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSystemTasks_8.png"><img class="alignnone size-medium wp-image-2102" title="Adware.Win32.WindowsSystemTasks" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSystemTasks_8-400x211.png" alt="Adware.Win32.WindowsSystemTasks" width="400" height="211" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSystemTasks_9.png"><img class="alignnone size-medium wp-image-2103" title="Adware.Win32.WindowsSystemTasks" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSystemTasks_9-400x325.png" alt="Adware.Win32.WindowsSystemTasks" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows System Tasks</strong><strong> </strong><strong> </strong><strong>(</strong><a title="Windows System Tasks" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSystemTasks" target="_blank"><strong>Adware.Win32.WindowsSystemTasks</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/05/24/windows-precautions-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Precautions Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/05/20/windows-system-tasks-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Protection Servant Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/05/20/windows-protection-servant-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/05/20/windows-protection-servant-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 20 May 2011 07:12:40 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Protection Servant]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2082</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Protection Servant adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsProtectionServant. Windows Protection Servant is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Protection Servant </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Adware.Win32.WindowsProtectionServant</strong></a><strong>.</strong></p>
<p><strong></strong><strong>Windows Protection Servant</strong><strong> </strong>is  a                rogue           application.                                      A         rogue                application  tries    to trick  you  by                             displaying                    false                       positive/misleading           scan              results                      report,  which   says           that  your                                     computer      has a     problem,        or     infected    with                        viruses    or           trojan,        but    you        will          not      be        able            to  fix    it           before you                   purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a title="Windows Activity Inspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Activity Inspector</strong></a></li>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a>,</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong>.</li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsProtectionServant_1.png"><img class="alignnone size-medium wp-image-2083" title="Adware.Win32.WindowsProtectionServant" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsProtectionServant_1-400x208.png" alt="Adware.Win32.WindowsProtectionServant" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsProtectionServant_2.png"><img class="alignnone size-medium wp-image-2084" title="Adware.Win32.WindowsProtectionServant" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsProtectionServant_2-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsProtectionServant_3.png"><img class="alignnone size-medium wp-image-2085" title="Adware.Win32.WindowsProtectionServant" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsProtectionServant_3-400x228.png" alt="Adware.Win32.WindowsProtectionServant" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsProtectionServant_4.png"><img class="alignnone size-medium wp-image-2086" title="Adware.Win32.WindowsProtectionServant" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsProtectionServant_4-400x228.png" alt="Adware.Win32.WindowsProtectionServant" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsProtectionServant_5.png"><img class="alignnone size-medium wp-image-2087" title="Adware.Win32.WindowsProtectionServant" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsProtectionServant_5-400x235.png" alt="Adware.Win32.WindowsProtectionServant" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsProtectionServant_6.png"><img class="alignnone size-medium wp-image-2088" title="Adware.Win32.WindowsProtectionServant" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsProtectionServant_6-400x214.png" alt="Adware.Win32.WindowsProtectionServant" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsProtectionServant_7.png"><img class="alignnone size-medium wp-image-2089" title="Adware.Win32.WindowsProtectionServant" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsProtectionServant_7-400x214.png" alt="Adware.Win32.WindowsProtectionServant" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsProtectionServant_8.png"><img class="alignnone size-medium wp-image-2090" title="Adware.Win32.WindowsProtectionServant" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsProtectionServant_8-400x214.png" alt="Adware.Win32.WindowsProtectionServant" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsProtectionServant_9.png"><img class="alignnone size-medium wp-image-2091" title="Adware.Win32.WindowsProtectionServant" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsProtectionServant_9-400x325.png" alt="Adware.Win32.WindowsProtectionServant" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows Protection Servant</strong><strong> </strong><strong> </strong><strong>(</strong><a title="Windows Protection Servant" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionServant" target="_blank"><strong>Adware.Win32.WindowsProtectionServant</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/16/windows-remedy-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Remedy Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/05/20/windows-protection-servant-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Activity Inspector Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/05/19/windows-activity-inspector-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/05/19/windows-activity-inspector-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 19 May 2011 12:55:04 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Activity Inspector]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2072</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Activity Inspector adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsActivityInspector. Windows Activity Inspector is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Activity Inspector </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Adware.Win32.WindowsActivityInspector</strong></a><strong>.</strong></p>
<p><strong></strong><strong>Windows Activity Inspector</strong><strong> </strong>is a                rogue           application.                                     A         rogue                application  tries    to trick you  by                             displaying                    false                      positive/misleading           scan             results                      report,  which   says           that  your                                    computer      has a     problem,       or     infected    with                        viruses    or          trojan,        but    you        will          not      be        able           to  fix    it           before you                   purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Windows Tweaking Utility</strong></a></li>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a>,</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong>.</li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsActivityInspector_1.png"><img class="alignnone size-medium wp-image-2073" title="Adware.Win32.WindowsActivityInspector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsActivityInspector_1-400x208.png" alt="Adware.Win32.WindowsActivityInspector" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsActivityInspector_2.png"><img class="alignnone size-medium wp-image-2074" title="Adware.Win32.WindowsActivityInspector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsActivityInspector_2-400x208.png" alt="Adware.Win32.WindowsActivityInspector" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsActivityInspector_3.png"><img class="alignnone size-medium wp-image-2075" title="Adware.Win32.WindowsActivityInspector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsActivityInspector_3-400x228.png" alt="Adware.Win32.WindowsActivityInspector" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsActivityInspector_4.png"><img class="alignnone size-medium wp-image-2076" title="Adware.Win32.WindowsActivityInspector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsActivityInspector_4-400x228.png" alt="Adware.Win32.WindowsActivityInspector" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsActivityInspector_5.png"><img class="alignnone size-medium wp-image-2077" title="Adware.Win32.WindowsActivityInspector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsActivityInspector_5-400x214.png" alt="Adware.Win32.WindowsActivityInspector" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsActivityInspector_6.png"><img class="alignnone size-medium wp-image-2078" title="Adware.Win32.WindowsActivityInspector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsActivityInspector_6-400x214.png" alt="Adware.Win32.WindowsActivityInspector" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsActivityInspector_7.png"><img class="alignnone size-medium wp-image-2079" title="Adware.Win32.WindowsActivityInspector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsActivityInspector_7-400x209.png" alt="Adware.Win32.WindowsActivityInspector" width="400" height="209" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsActivityInspector_8.png"><img class="alignnone size-medium wp-image-2080" title="Adware.Win32.WindowsActivityInspector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsActivityInspector_8-400x325.png" alt="Adware.Win32.WindowsActivityInspector" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows Activity Inspector</strong><strong> </strong><strong> </strong><strong>(</strong><a title="WindowsTweakingUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTweakingUtility" target="_blank"><a title="WindowsActivityInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityInspector" target="_blank"><strong>Adware.Win32.WindowsActivityInspector</strong></a><strong></strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/05/20/windows-protection-servant-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Protection Servant Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/05/20/windows-system-tasks-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows System Tasks Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/05/24/windows-precautions-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Precautions Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/05/24/windows-repairing-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Repairing System Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/05/19/windows-activity-inspector-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Win XP Recovery Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/05/17/windows-xp-recovery-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/05/17/windows-xp-recovery-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 17 May 2011 12:38:49 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows XP Recovery]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2064</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the WinXPRecovery adware or also known as Windows XP Recovery. Emsisoft Anti-Malware detects this malware as Adware.Win32.WinXPRecovery. Windows XP Recovery is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>WinXPRecovery </strong>adware or also known as <strong>Windows XP Recovery</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinXPRecovery" target="_blank"><strong>Adware.Win32.WinXPRecovery</strong></a><strong>.</strong></p>
<p><strong>Windows XP Recovery </strong>is a rogue    application.                                       A  rogue   application  tries    to trick     you  by                  displaying         false                  positive/misleading        scan       results         report,  which       says        that  your                   computer    has a    problem,         or     infected with          viruses    or       trojan,       but     you      will    not   be    able          to fix it         before  you            purchase.</p>
<p><strong>Variants of the rogue defragmenter:</strong> <strong></strong></p>
<ul>
<li><a title="WindowsRestore" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRestore" target="_blank"><strong>Windows Restore</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepair" target="_blank"><strong>Windows Repair</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRecovery" target="_blank"><strong>Windows Recovery</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDiagnostic" target="_blank"><strong>Windows Diagnostic</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinScan" target="_blank"><strong>Win Scan</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinDisk" target="_blank"><strong>Win Disk</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DiskRecovery" target="_blank"><strong>Disk Recovery</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDisk" target="_blank"><strong>Windows Disk</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsScan" target="_blank"><strong>Windows Scan</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MemoryOptimizer" target="_blank"><strong>Memory Optimizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DiskOptimizer" target="_blank"><strong>Disk Optimizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.EasyScan" target="_blank"><strong>Easy Scan</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GoodMemory" target="_blank"><strong>Good Memory</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.FastDisk" target="_blank"><strong>Fast Disk</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DiskOK" target="_blank"><strong>Disk OK</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MyDisk" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MyDisk" target="_blank"><strong>My Disk</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MemoryFixer" target="_blank"><strong>Memory Fixer</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDFix" target="_blank">HDD Fix</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DefragScanner" target="_blank"><strong>Scanner</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDLow" target="_blank"><strong>HDD Low</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DiskRepair" target="_blank"><strong>Disk Repair</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.Defragmenter" target="_blank"><strong>Defragmenter</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDTools" target="_blank"><strong>HDD Tools</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartHDD" target="_blank"><strong>Smart HDD</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDRescue" target="_blank"><strong>HDD Rescue</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDPlus" target="_blank"><strong>HDD Plus</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDDiagnostic" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDDiagnostic" target="_blank"><strong>HDD Diagnostic</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HardDriveDiagnostic" target="_blank"><strong>Hard Drive Diagnostic</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DiskDoctor" target="_blank"><strong>Disk Doctor</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinDefragmenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinDefragmenter" target="_blank"><strong>Win Defragmenter</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinDefrag" target="_blank"><strong>WinDefrag</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinHDD" target="_blank"><strong>WinHDD</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.CheckDisk" target="_blank"><strong>CheckDisk</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.UltraDefragger" target="_blank"><strong>Ultra Defragger</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.QuickDefragmenter" target="_blank"><strong>Quick Defragmenter</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartDefragmenter" target="_blank"><strong>Smart Defragmenter</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDDefragmenter" target="_blank"><strong>HDD Defragmenter</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemDefragmenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemDefragmenter" target="_blank"><strong>System Defragmenter</strong></a></li>
</ul>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\~%random%</li>
<li>%AllUsersProfile%\Application Data\~%random%</li>
<li>%AllUsersProfile%\Application Data\%random%</li>
<li>%AllUsersProfile%\Application Data\%random%.exe</li>
<li>%UserProfile%\Desktop\Windows XP Recovery.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Windows XP Recovery\</li>
<li>%UserProfile%\Start Menu\Programs\Windows XP Recovery\Uninstall Windows XP Recovery.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Windows XP Recovery\Windows XP Recovery.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\<br />
DisableTaskMgr: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\<br />
75fa38b7-8b94-4995-ad32-52e938867954:<br />
BD: 43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 74 00 73 00 20 00 61 00…</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\<br />
Use FormSuggest: “Yes”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\<br />
WarnonBadCertRecving: 0×00000000<br />
CertificateRevocation: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\<br />
NoChangingWallPaper: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\<br />
LowRiskFileTypes:     “/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\<br />
SaveZoneInformation: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Policies\Explorer<br />
NoDesktop = 0&#215;00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\<br />
DisableTaskMgr: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
%random%: “%AllUsersProfile%\Application Data\%random%.exe”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures: “no”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
Hidden: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
ShowSuperHidden: 0×00000000</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WinXPRecovery_3.png"><img class="alignnone size-medium wp-image-2065" title="Adware.Win32.WinXPRecovery" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WinXPRecovery_3-400x240.png" alt="Adware.Win32.WinXPRecovery" width="400" height="240" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WinXPRecovery_4.png"><img class="alignnone size-medium wp-image-2066" title="Adware.Win32.WinXPRecovery" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WinXPRecovery_4-400x240.png" alt="Adware.Win32.WinXPRecovery" width="400" height="240" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WinXPRecovery_5.png"><img class="alignnone size-medium wp-image-2067" title="Adware.Win32.WinXPRecovery" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WinXPRecovery_5-400x240.png" alt="Adware.Win32.WinXPRecovery" width="400" height="240" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WinXPRecovery_6.png"><img class="alignnone size-medium wp-image-2068" title="Adware.Win32.WinXPRecovery" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WinXPRecovery_6-400x104.png" alt="Adware.Win32.WinXPRecovery" width="400" height="104" /></a></strong></p>
<p><strong>How to remove the infection of </strong><strong>Windows XP Recovery </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinXPRecovery" target="_blank">Adware.Win32.WinXPRecovery</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/04/05/windows-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/08/disk-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">Disk Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/04/08/windows-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/04/05/windows-repair-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Repair Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/08/win-disk-adware-removal-instructions/" rel="bookmark" class="crp_title">Win Disk Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/05/17/windows-xp-recovery-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Tweaking Utility Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/05/17/windows-tweaking-utility-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/05/17/windows-tweaking-utility-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 17 May 2011 12:16:22 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Tweaking Utility]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2053</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Tweaking Utility adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsTweakingUtility. Windows Tweaking Utility is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Tweaking Utility </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="WindowsTweakingUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTweakingUtility" target="_blank"><strong>Adware.Win32.WindowsTweakingUtility</strong></a><strong>.</strong></p>
<p><strong>Windows Tweaking Utility</strong><strong> </strong>is a               rogue           application.                                    A         rogue                application  tries    to trick you  by                            displaying                    false                     positive/misleading           scan             results                     report,  which   says           that  your                                   computer      has a     problem,       or     infected   with                        viruses    or          trojan,        but   you        will          not      be        able           to  fix   it           before you                   purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Windows Inspection Utility</strong><strong></strong></a></li>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a>,</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong>.</li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsTweakingUtility_1.png"><img class="alignnone size-medium wp-image-2054" title="Adware.Win32.WindowsTweakingUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsTweakingUtility_1-400x208.png" alt="Adware.Win32.WindowsTweakingUtility" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsTweakingUtility_2.png"><img class="alignnone size-medium wp-image-2055" title="Adware.Win32.WindowsTweakingUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsTweakingUtility_2-400x208.png" alt="Adware.Win32.WindowsTweakingUtility" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsTweakingUtility_3.png"><img class="alignnone size-medium wp-image-2056" title="Adware.Win32.WindowsTweakingUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsTweakingUtility_3-400x228.png" alt="Adware.Win32.WindowsTweakingUtility" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsTweakingUtility_4.png"><img class="alignnone size-medium wp-image-2057" title="Adware.Win32.WindowsTweakingUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsTweakingUtility_4-400x228.png" alt="Adware.Win32.WindowsTweakingUtility" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsTweakingUtility_5.png"><img class="alignnone size-medium wp-image-2058" title="Adware.Win32.WindowsTweakingUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsTweakingUtility_5-400x235.png" alt="Adware.Win32.WindowsTweakingUtility" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsTweakingUtility_6.png"><img class="alignnone size-medium wp-image-2059" title="Adware.Win32.WindowsTweakingUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsTweakingUtility_6-400x214.png" alt="Adware.Win32.WindowsTweakingUtility" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsTweakingUtility_7.png"><img class="alignnone size-medium wp-image-2060" title="Adware.Win32.WindowsTweakingUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsTweakingUtility_7-400x214.png" alt="Adware.Win32.WindowsTweakingUtility" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsTweakingUtility_8.png"><img class="alignnone size-medium wp-image-2061" title="Adware.Win32.WindowsTweakingUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsTweakingUtility_8-400x211.png" alt="Adware.Win32.WindowsTweakingUtility" width="400" height="211" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsTweakingUtility_9.png"><img class="alignnone size-medium wp-image-2062" title="Adware.Win32.WindowsTweakingUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsTweakingUtility_9-400x325.png" alt="Adware.Win32.WindowsTweakingUtility" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows Tweaking Utility</strong><strong> </strong><strong> </strong><strong>(</strong><a title="WindowsTweakingUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTweakingUtility" target="_blank"><strong>Adware.Win32.WindowsTweakingUtility</strong><strong></strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/05/19/windows-activity-inspector-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Inspector Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-defence-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Defence Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/22/windows-av-software-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows AV Software Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/05/17/windows-tweaking-utility-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Inspection Utility Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/05/12/windows-inspection-utility-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/05/12/windows-inspection-utility-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 12 May 2011 12:48:06 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Inspection Utility]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2040</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Inspection Utility adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsInspectionUtility. Windows Inspection Utility is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Inspection Utility </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Adware.Win32.WindowsInspectionUtility</strong></a><strong>.</strong></p>
<p><strong>Windows Inspection Utility</strong><strong> </strong>is a              rogue           application.                                   A         rogue                application  tries    to trick you  by                           displaying                    false                    positive/misleading           scan             results                    report,  which   says           that  your                                  computer      has a     problem,       or     infected  with                        viruses    or          trojan,        but  you        will          not      be        able           to  fix   it          before you                   purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong></strong></li>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a>,</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong>.</li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsInspectionUtility_1.png"><img class="alignnone size-medium wp-image-2041" title="Adware.Win32.WindowsInspectionUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsInspectionUtility_1-400x208.png" alt="Adware.Win32.WindowsInspectionUtility" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsInspectionUtility_2.png"><img class="alignnone size-medium wp-image-2042" title="Adware.Win32.WindowsInspectionUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsInspectionUtility_2-400x208.png" alt="Adware.Win32.WindowsInspectionUtility" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsInspectionUtility_3.png"><img class="alignnone size-medium wp-image-2043" title="Adware.Win32.WindowsInspectionUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsInspectionUtility_3-400x228.png" alt="Adware.Win32.WindowsInspectionUtility" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsInspectionUtility_4.png"><img class="alignnone size-medium wp-image-2044" title="Adware.Win32.WindowsInspectionUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsInspectionUtility_4-400x228.png" alt="Adware.Win32.WindowsInspectionUtility" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsInspectionUtility_5.png"><img class="alignnone size-medium wp-image-2045" title="Adware.Win32.WindowsInspectionUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsInspectionUtility_5-400x235.png" alt="Adware.Win32.WindowsInspectionUtility" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsInspectionUtility_6.png"><img class="alignnone size-medium wp-image-2046" title="Adware.Win32.WindowsInspectionUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsInspectionUtility_6-400x214.png" alt="Adware.Win32.WindowsInspectionUtility" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsInspectionUtility_7.png"><img class="alignnone size-medium wp-image-2047" title="Adware.Win32.WindowsInspectionUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsInspectionUtility_7-400x214.png" alt="Adware.Win32.WindowsInspectionUtility" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsInspectionUtility_8.png"><img class="alignnone size-medium wp-image-2048" title="Adware.Win32.WindowsInspectionUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsInspectionUtility_8-400x214.png" alt="Adware.Win32.WindowsInspectionUtility" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsInspectionUtility_9.png"><img class="alignnone size-medium wp-image-2049" title="Adware.Win32.WindowsInspectionUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsInspectionUtility_9-400x325.png" alt="" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows Inspection Utility</strong><strong> </strong><strong> </strong><strong>(</strong><a title="WindowsInspectionUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInspectionUtility" target="_blank"><strong>Adware.Win32.WindowsInspectionUtility</strong></a><strong></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/05/17/windows-tweaking-utility-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Tweaking Utility Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/05/19/windows-activity-inspector-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Inspector Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/05/20/windows-protection-servant-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Protection Servant Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/05/12/windows-inspection-utility-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Supervision Center Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/05/12/windows-supervision-center-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/05/12/windows-supervision-center-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 12 May 2011 12:00:06 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Supervision Center]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2030</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Supervision Center adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsSupervisionCenter. Windows Supervision Center is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Supervision Center </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Adware.Win32.WindowsSupervisionCenter</strong></a><strong>.</strong></p>
<p><strong>Windows Supervision Center</strong><strong> </strong>is a             rogue           application.                                   A        rogue                application  tries    to trick you  by                          displaying                    false                   positive/misleading           scan             results                   report,  which   says           that  your                                 computer      has a     problem,       or     infected  with                       viruses    or          trojan,        but  you       will          not      be        able           to  fix   it         before you                   purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a title="WindowsOversightCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Windows Oversight Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a>,</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong>.</li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSupervisionCenter_1.png"><img class="alignnone size-medium wp-image-2031" title="Adware.Win32.WindowsSupervisionCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSupervisionCenter_1-400x208.png" alt="Adware.Win32.WindowsSupervisionCenter" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSupervisionCenter_2.png"><img class="alignnone size-medium wp-image-2032" title="Adware.Win32.WindowsSupervisionCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSupervisionCenter_2-400x208.png" alt="Adware.Win32.WindowsSupervisionCenter" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSupervisionCenter_3.png"><img class="alignnone size-medium wp-image-2033" title="Adware.Win32.WindowsSupervisionCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSupervisionCenter_3-400x228.png" alt="Adware.Win32.WindowsSupervisionCenter" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSupervisionCenter_4.png"><img class="alignnone size-medium wp-image-2034" title="Adware.Win32.WindowsSupervisionCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSupervisionCenter_4-400x228.png" alt="Adware.Win32.WindowsSupervisionCenter" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSupervisionCenter_5.png"><img class="alignnone size-medium wp-image-2035" title="Adware.Win32.WindowsSupervisionCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSupervisionCenter_5-400x235.png" alt="Adware.Win32.WindowsSupervisionCenter" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSupervisionCenter_6.png"><img class="alignnone size-medium wp-image-2036" title="Adware.Win32.WindowsSupervisionCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSupervisionCenter_6-400x214.png" alt="Adware.Win32.WindowsSupervisionCenter" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSupervisionCenter_7.png"><img class="alignnone size-medium wp-image-2037" title="Adware.Win32.WindowsSupervisionCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSupervisionCenter_7-400x214.png" alt="Adware.Win32.WindowsSupervisionCenter" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSupervisionCenter_8.png"><img class="alignnone size-medium wp-image-2038" title="Adware.Win32.WindowsSupervisionCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsSupervisionCenter_8-400x214.png" alt="Adware.Win32.WindowsSupervisionCenter" width="400" height="214" /></a></strong></p>
<p><strong>How to remove the infection of Windows Supervision Center</strong><strong> </strong><strong> </strong><strong>(<a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank">Adware.Win32.</a></strong><a title="WindowsSupervisionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupervisionCenter" target="_blank"><strong>Windows Supervision Center</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/05/12/windows-inspection-utility-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Inspection Utility Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/05/17/windows-tweaking-utility-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Tweaking Utility Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/05/19/windows-activity-inspector-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Inspector Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/05/12/windows-supervision-center-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Oversight Center Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/05/10/windows-oversight-center-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/05/10/windows-oversight-center-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 10 May 2011 08:13:27 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2019</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Oversight Center adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsOversightCenter. Windows Oversight Center is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Oversight Center </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank"><strong>Adware.Win32.WindowsOversightCenter</strong></a><strong>.</strong></p>
<p><strong>Windows Oversight Center</strong><strong> </strong>is a            rogue           application.                                   A       rogue                application  tries    to trick you  by                         displaying                    false                  positive/misleading           scan             results                  report,  which   says           that  your                                computer      has a     problem,       or     infected  with                      viruses    or          trojan,        but  you       will         not      be        able           to  fix   it         before you                  purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Windows Passport Utility</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a>,</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong>.</li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsOversightCenter_1.png"><img class="alignnone size-medium wp-image-2020" title="Adware.Win32.WindowsOversightCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsOversightCenter_1-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsOversightCenter_3.png"><img class="alignnone size-medium wp-image-2021" title="Adware.Win32.WindowsOversightCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsOversightCenter_3-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsOversightCenter_4.png"><img class="alignnone size-medium wp-image-2022" title="Adware.Win32.WindowsOversightCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsOversightCenter_4-400x228.png" alt="" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsOversightCenter_5.png"><img class="alignnone size-medium wp-image-2023" title="Adware.Win32.WindowsOversightCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsOversightCenter_5-400x228.png" alt="" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsOversightCenter_7.png"><img class="alignnone size-medium wp-image-2024" title="Adware.Win32.WindowsOversightCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsOversightCenter_7-400x235.png" alt="" width="400" height="235" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsOversightCenter_8.png"><img class="alignnone size-medium wp-image-2025" title="Adware.Win32.WindowsOversightCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsOversightCenter_8-400x214.png" alt="" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsOversightCenter_9.png"><img class="alignnone size-medium wp-image-2026" title="Adware.Win32.WindowsOversightCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsOversightCenter_9-400x214.png" alt="" width="400" height="214" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsOversightCenter_10.png"><img class="alignnone size-medium wp-image-2027" title="Adware.Win32.WindowsOversightCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsOversightCenter_10-400x211.png" alt="" width="400" height="211" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsOversightCenter_11.png"><img class="alignnone size-medium wp-image-2028" title="Adware.Win32.WindowsOversightCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.WindowsOversightCenter_11-400x325.png" alt="" width="400" height="325" /></a></strong></p>
<p><strong>How to remove the infection of Windows Oversight Center</strong><strong> </strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOversightCenter" target="_blank">Adware.Win32.WindowsOversightCenter</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-defence-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Defence Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/05/12/windows-supervision-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Supervision Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/05/10/windows-oversight-center-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FakeBitDef2011 Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/05/04/fakebitdef2011-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/05/04/fakebitdef2011-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 04 May 2011 18:15:22 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeBitDef2011]]></category>
		<category><![CDATA[Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2009</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Fake BitDefender 2011 or FakeBitDef2011 adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.FakeBitDef2011. FakeBitDef2011 is a rogue application. The maker of this rogue, gave it the same name as one of the security product.  A rogue application tries to trick you by displaying [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Fake BitDefender 2011</strong> or <strong>FakeBitDef2011 </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.FakeBitDef2011" target="_blank"><strong>Adware.Win32.</strong><strong>FakeBitDef2011</strong></a><strong>.</strong></p>
<p><strong>FakeBitDef2011 </strong>is a rogue    application. The maker of this rogue, gave it the same name as one of the security product.                                        A  rogue   application  tries    to  trick     you  by                  displaying         false                   positive or misleading        scan       results         report,   which       says        that  your                   computer    has a     problem,         or     infected with          viruses    or        trojan,       but     you      will    not   be    able          to fix  it         before  you            purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\BitDefender 2011\</li>
<li>%ProgramFiles%\BitDefender 2011\bitdefender.exe</li>
<li>%Windir%\system32\iesafemode.exe</li>
<li>%AllUsersProfile%\Start Menu\BitDefender 2011\</li>
<li>%AllUsersProfile%\Start Menu\BitDefender 2011\BitDefender 2011.lnk</li>
<li>%AllUsersProfile%\Start Menu\BitDefender 2011\Uninstall.lnk</li>
<li>%UserProfile%\Desktop\BitDefender 2011.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\chrome.exe\<br />
Debugger: &#8220;iesafemode.exe -sb&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\firefox.exe\<br />
Debugger: &#8220;iesafemode.exe -sb&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplore.exe\<br />
Debugger: &#8220;iesafemode.exe -sb&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\opera.exe\<br />
Debugger: &#8220;iesafemode.exe -sb&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safari.exe\<br />
Debugger: &#8220;iesafemode.exe -sb&#8221;</li>
<li>HKEY_CURRENT_USER\Software\EVA40A\</li>
<li>HKEY_CURRENT_USER\Software\Mon40A\</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
BitDefender 2011: &#8220;%ProgramFiles%\BitDefender 2011\bitdefender.exe&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.FakeBitDef2011_1.png"><img class="alignnone size-medium wp-image-2010" title="Adware.Win32.FakeBitDef2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.FakeBitDef2011_1-400x262.png" alt="" width="400" height="262" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.FakeBitDef2011_2.png"><img class="alignnone size-medium wp-image-2011" title="Adware.Win32.FakeBitDef2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.FakeBitDef2011_2-400x247.png" alt="" width="400" height="247" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.FakeBitDef2011_3.png"><img class="alignnone size-medium wp-image-2012" title="Adware.Win32.FakeBitDef2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.FakeBitDef2011_3-400x319.png" alt="" width="400" height="319" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.FakeBitDef2011_4.png"><img class="alignnone size-medium wp-image-2013" title="Adware.Win32.FakeBitDef2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.FakeBitDef2011_4-400x262.png" alt="" width="400" height="262" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.FakeBitDef2011_5.png"><img class="alignnone size-medium wp-image-2014" title="Adware.Win32.FakeBitDef2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.FakeBitDef2011_5-400x194.png" alt="" width="400" height="194" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.FakeBitDef2011_6.png"><img class="alignnone size-full wp-image-2015" title="Adware.Win32.FakeBitDef2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/05/Adware.Win32.FakeBitDef2011_6.png" alt="" width="310" height="143" /></a></p>
<p><strong>How to remove the infection of </strong><strong>FakeBitDef2011 </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.FakeBitDef2011" target="_blank">Adware.Win32.</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.FakeBitDef2011" target="_blank"><strong>FakeBitDef2011</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/12/13/antivirii-2011-rogue-removal-instructions/" rel="bookmark" class="crp_title">Antivirii 2011 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/02/windows-health-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Health Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/09/windows-software-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/04/windows-problems-protector-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Problems Protector Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/11/windows-software-guard-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Guard Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/05/04/fakebitdef2011-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Antivirus Clean 2011 Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/04/13/antivirus-clean-2011-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/04/13/antivirus-clean-2011-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 13 Apr 2011 16:01:02 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Antivirus Clean 2011]]></category>
		<category><![CDATA[Instructions]]></category>
		<category><![CDATA[Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2001</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Antivirus Clean 2011 adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.AntivirusClean2011. Antivirus Clean 2011 is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Antivirus Clean 2011 </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirusClean2011" target="_blank"><strong>Adware.Win32.AntivirusClean2011</strong></a><strong>.</strong></p>
<p><strong>Antivirus Clean 2011 </strong>is a rogue    application.                                       A  rogue   application  tries    to trick     you  by                  displaying         false                  positive/misleading        scan       results         report,  which       says        that  your                   computer    has a    problem,         or     infected with          viruses    or       trojan,       but     you      will    not   be    able          to fix it         before  you            purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\Antivirus Clean 2011\</li>
<li>%ProgramFiles%\Antivirus Clean 2011\avservice.exe</li>
<li>%ProgramFiles%\Antivirus Clean 2011\avsetup.exe</li>
<li>%ProgramFiles%\Antivirus Clean 2011\avc2011.exe</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run<br />
AntivirusClean = %ProgramFiles%\Antivirus Clean 2011\avc2011.exe<br />
avservice = %ProgramFiles%\Antivirus Clean 2011\avservice.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.AntivirusClean2011_1.png"><img class="alignnone size-medium wp-image-2002" title="Adware.Win32.AntivirusClean2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.AntivirusClean2011_1-400x326.png" alt="" width="400" height="326" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.AntivirusClean2011_2.png"><img class="alignnone size-medium wp-image-2003" title="Adware.Win32.AntivirusClean2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.AntivirusClean2011_2-370x400.png" alt="" width="370" height="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.AntivirusClean2011_3.png"><img class="alignnone size-medium wp-image-2004" title="Adware.Win32.AntivirusClean2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.AntivirusClean2011_3-400x209.png" alt="" width="400" height="209" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.AntivirusClean2011_4.png"><img class="alignnone size-medium wp-image-2005" title="Adware.Win32.AntivirusClean2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.AntivirusClean2011_4-400x222.png" alt="" width="400" height="222" /></a></p>
<p><strong>How to remove the infection of </strong><strong>Antivirus Clean 2011 </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirusClean2011" target="_blank">Adware.Win32.AntivirusClean2011</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/08/antivirus-antispyware-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">AntiVirus AntiSpyware 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/13/wolfram-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">Wolfram Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/05/blueflare-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">BlueFlare Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/29/opencloud-antivirus-adware-removal-instructions/" rel="bookmark" class="crp_title">OpenCloud Antivirus Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/19/security-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Protection Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/04/13/antivirus-clean-2011-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Restore Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/04/08/windows-restore-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/04/08/windows-restore-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 08 Apr 2011 06:55:33 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Restore]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=1994</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Restore adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsRestore. Windows Restore is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with viruses or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Restore </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRestore" target="_blank"><strong>Adware.Win32.WindowsRestore</strong></a><strong>.</strong></p>
<p><strong>Windows Restore </strong>is a rogue    application.                                      A  rogue   application  tries    to trick    you  by                  displaying         false                 positive/misleading        scan       results         report,  which      says        that  your                   computer    has a    problem,        or     infected with          viruses    or       trojan,      but     you      will    not   be    able          to fix it        before  you            purchase.</p>
<p><strong>Variants of the rogue defragmenter:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepair" target="_blank"><strong>Windows Repair</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRecovery" target="_blank"><strong>Windows Recovery</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDiagnostic" target="_blank"><strong>Windows Diagnostic</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinScan" target="_blank"><strong>Win Scan</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinDisk" target="_blank"><strong>Win Disk</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DiskRecovery" target="_blank"><strong>Disk Recovery</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDisk" target="_blank"><strong>Windows Disk</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsScan" target="_blank"><strong>Windows Scan</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MemoryOptimizer" target="_blank"><strong>Memory Optimizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DiskOptimizer" target="_blank"><strong>Disk Optimizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.EasyScan" target="_blank"><strong>Easy Scan</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GoodMemory" target="_blank"><strong>Good Memory</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.FastDisk" target="_blank"><strong>Fast Disk</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DiskOK" target="_blank"><strong>Disk OK</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MyDisk" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MyDisk" target="_blank"><strong>My Disk</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MemoryFixer" target="_blank"><strong>Memory Fixer</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDFix" target="_blank">HDD Fix</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DefragScanner" target="_blank"><strong>Scanner</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDLow" target="_blank"><strong>HDD Low</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DiskRepair" target="_blank"><strong>Disk Repair</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.Defragmenter" target="_blank"><strong>Defragmenter</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDTools" target="_blank"><strong>HDD Tools</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartHDD" target="_blank"><strong>Smart HDD</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDRescue" target="_blank"><strong>HDD Rescue</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDPlus" target="_blank"><strong>HDD Plus</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDDiagnostic" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDDiagnostic" target="_blank"><strong>HDD Diagnostic</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HardDriveDiagnostic" target="_blank"><strong>Hard Drive Diagnostic</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DiskDoctor" target="_blank"><strong>Disk Doctor</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinDefragmenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinDefragmenter" target="_blank"><strong>Win Defragmenter</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinDefrag" target="_blank"><strong>WinDefrag</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinHDD" target="_blank"><strong>WinHDD</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.CheckDisk" target="_blank"><strong>CheckDisk</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.UltraDefragger" target="_blank"><strong>Ultra Defragger</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.QuickDefragmenter" target="_blank"><strong>Quick Defragmenter</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartDefragmenter" target="_blank"><strong>Smart Defragmenter</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDDefragmenter" target="_blank"><strong>HDD Defragmenter</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemDefragmenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemDefragmenter" target="_blank"><strong>System Defragmenter</strong></a></li>
</ul>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\%random%</li>
<li>%AllUsersProfile%\Application Data\%random%.exe</li>
<li>%AllUsersProfile%\Application Data\%random%.exe</li>
<li>%UserProfile%\Desktop\Windows Restore.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Windows Restore\</li>
<li>%UserProfile%\Start Menu\Programs\Windows Restore\Uninstall Windows Restore.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Windows Restore\Windows Restore.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\<br />
DisableTaskMgr: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\<br />
75fa38b7-8b94-4995-ad32-52e938867954:<br />
BD: 43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 74 00 73 00 20 00 61 00…</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\<br />
Use FormSuggest: “Yes”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\<br />
WarnonBadCertRecving: 0×00000000<br />
CertificateRevocation: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\<br />
NoChangingWallPaper: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\<br />
LowRiskFileTypes:    “/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\<br />
SaveZoneInformation: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\<br />
DisableTaskMgr: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
%random%: “%AllUsersProfile%\Application Data\%random%.exe”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures: “no”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
Hidden: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
ShowSuperHidden: 0×00000000</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRestore_1.png"><img class="alignnone size-medium wp-image-1995" title="Adware.Win32.WindowsRestore" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRestore_1-400x268.png" alt="" width="400" height="268" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRestore_2.png"><img class="alignnone size-medium wp-image-1996" title="Adware.Win32.WindowsRestore" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRestore_2-400x268.png" alt="" width="400" height="268" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRestore_3.png"><img class="alignnone size-medium wp-image-1997" title="Adware.Win32.WindowsRestore" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRestore_3-400x268.png" alt="" width="400" height="268" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRestore_4.png"><img class="alignnone size-medium wp-image-1998" title="Adware.Win32.WindowsRestore" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRestore_4-400x268.png" alt="" width="400" height="268" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRestore_5.png"><img class="alignnone size-medium wp-image-1999" title="Adware.Win32.WindowsRestore" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRestore_5-400x219.png" alt="" width="400" height="219" /></a></strong></p>
<p><strong>How to remove the infection of </strong><strong>Windows Restore </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRestore" target="_blank">Adware.Win32.WindowsRestore</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/05/17/windows-xp-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">Win XP Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/04/05/windows-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/04/05/windows-repair-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Repair Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/08/disk-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">Disk Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/04/windows-disk-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Disk Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/04/08/windows-restore-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Passport Utility Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/04/05/windows-passport-utility-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/04/05/windows-passport-utility-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 05 Apr 2011 09:12:29 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Passport Utility]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=1984</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Passport Utility adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsPassportUtility. Windows Passport Utility is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Passport Utility </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank"><strong>Adware.Win32.WindowsPassportUtility</strong></a><strong>.</strong></p>
<p><strong>Windows Passport Utility</strong><strong> </strong>is a           rogue           application.                                   A      rogue                application  tries    to trick you  by                        displaying                    false                 positive/misleading           scan             results                 report,  which   says           that  your                               computer      has a     problem,       or     infected  with                     viruses    or          trojan,        but  you       will        not      be        able           to  fix   it         before you                 purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Windows Process Regulator</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a>,</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong>.</li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPassportUtility_1.png"><img class="alignnone size-medium wp-image-1985" title="Adware.Win32.WindowsPassportUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPassportUtility_1-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPassportUtility_2.png"><img class="alignnone size-medium wp-image-1986" title="Adware.Win32.WindowsPassportUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPassportUtility_2-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPassportUtility_3.png"><img class="alignnone size-medium wp-image-1987" title="Adware.Win32.WindowsPassportUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPassportUtility_3-400x228.png" alt="" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPassportUtility_4.png"><img class="alignnone size-medium wp-image-1988" title="Adware.Win32.WindowsPassportUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPassportUtility_4-400x228.png" alt="" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPassportUtility_5.png"><img class="alignnone size-full wp-image-1989" title="Adware.Win32.WindowsPassportUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPassportUtility_5.png" alt="" width="396" height="254" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPassportUtility_6.png"><img class="alignnone size-medium wp-image-1990" title="Adware.Win32.WindowsPassportUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPassportUtility_6-400x270.png" alt="" width="400" height="270" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPassportUtility_7.png"><img class="alignnone size-medium wp-image-1991" title="Adware.Win32.WindowsPassportUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPassportUtility_7-400x270.png" alt="" width="400" height="270" /></a></strong></p>
<p><strong>How to remove the infection of Windows Passport Utility</strong><strong> </strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPassportUtility" target="_blank">Adware.Win32.WindowsPassportUtility</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-defence-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Defence Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/16/windows-remedy-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Remedy Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/04/05/windows-passport-utility-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Process Regulator Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/04/05/windows-process-regulator-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/04/05/windows-process-regulator-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 05 Apr 2011 09:02:12 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Process Regulator]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=1974</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Process Regulator adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsProcessRegulator. Windows Process Regulator is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Process Regulator </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong>Adware.Win32.WindowsProcessRegulator</strong></a><strong>.</strong></p>
<p><strong>Windows Process Regulator</strong><strong> </strong>is a          rogue           application.                                   A     rogue                application  tries    to trick you  by                       displaying                    false                positive/misleading           scan             results                report,  which   says           that  your                              computer      has a     problem,       or     infected  with                    viruses    or          trojan,        but  you       will       not      be        able           to  fix   it         before you                purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Windows Simple Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a>,</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong>.</li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsProcessRegulator_1.png"><img class="alignnone size-medium wp-image-1975" title="Adware.Win32.WindowsProcessRegulator" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsProcessRegulator_1-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsProcessRegulator_2.png"><img class="alignnone size-medium wp-image-1976" title="Adware.Win32.WindowsProcessRegulator" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsProcessRegulator_2-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsProcessRegulator_3.png"><img class="alignnone size-medium wp-image-1977" title="Adware.Win32.WindowsProcessRegulator" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsProcessRegulator_3-400x228.png" alt="" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsProcessRegulator_4.png"><img class="alignnone size-medium wp-image-1978" title="Adware.Win32.WindowsProcessRegulator" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsProcessRegulator_4-400x228.png" alt="" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsProcessRegulator_5.png"><img class="alignnone size-full wp-image-1979" title="Adware.Win32.WindowsProcessRegulator" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsProcessRegulator_5.png" alt="" width="396" height="254" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsProcessRegulator_6.png"><img class="alignnone size-medium wp-image-1980" title="Adware.Win32.WindowsProcessRegulator" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsProcessRegulator_6-400x270.png" alt="" width="400" height="270" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsProcessRegulator_7.png"><img class="alignnone size-medium wp-image-1981" title="Adware.Win32.WindowsProcessRegulator" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsProcessRegulator_7-400x270.png" alt="" width="400" height="270" /></a></strong></p>
<p><strong>How to remove the infection of Windows Process Regulator</strong><strong> </strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank">Adware.Win32.WindowsProcessRegulator</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessRegulator" target="_blank"><strong></strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-defence-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Defence Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/04/01/windows-stability-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Stability Center Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/04/05/windows-process-regulator-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Repair Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/04/05/windows-repair-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/04/05/windows-repair-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 05 Apr 2011 08:53:36 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Repair]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=1966</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Repair adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsRepair. Windows Repair is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with viruses or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Repair </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepair" target="_blank"><strong>Adware.Win32.WindowsRepair</strong></a><strong>.</strong></p>
<p><strong>Windows Repair </strong>is a rogue    application.                                     A  rogue   application  tries    to trick   you  by                  displaying         false                positive/misleading        scan       results         report,  which     says        that  your                   computer    has a    problem,       or     infected with          viruses    or       trojan,      but    you      will    not   be    able          to fix it        before you            purchase.</p>
<p><strong>Variants of the rogue defragmenter:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRecovery" target="_blank"><strong>Windows Recovery</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDiagnostic" target="_blank"><strong>Windows Diagnostic</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinScan" target="_blank"><strong>Win Scan</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinDisk" target="_blank"><strong>Win Disk</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DiskRecovery" target="_blank"><strong>Disk Recovery</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDisk" target="_blank"><strong>Windows Disk</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsScan" target="_blank"><strong>Windows Scan</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MemoryOptimizer" target="_blank"><strong>Memory Optimizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DiskOptimizer" target="_blank"><strong>Disk Optimizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.EasyScan" target="_blank"><strong>Easy Scan</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GoodMemory" target="_blank"><strong>Good Memory</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.FastDisk" target="_blank"><strong>Fast Disk</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DiskOK" target="_blank"><strong>Disk OK</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MyDisk" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MyDisk" target="_blank"><strong>My Disk</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MemoryFixer" target="_blank"><strong>Memory Fixer</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDFix" target="_blank">HDD Fix</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DefragScanner" target="_blank"><strong>Scanner</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDLow" target="_blank"><strong>HDD Low</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DiskRepair" target="_blank"><strong>Disk Repair</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.Defragmenter" target="_blank"><strong>Defragmenter</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDTools" target="_blank"><strong>HDD Tools</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartHDD" target="_blank"><strong>Smart HDD</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDRescue" target="_blank"><strong>HDD Rescue</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDPlus" target="_blank"><strong>HDD Plus</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDDiagnostic" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDDiagnostic" target="_blank"><strong>HDD Diagnostic</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HardDriveDiagnostic" target="_blank"><strong>Hard Drive Diagnostic</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DiskDoctor" target="_blank"><strong>Disk Doctor</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinDefragmenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinDefragmenter" target="_blank"><strong>Win Defragmenter</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinDefrag" target="_blank"><strong>WinDefrag</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinHDD" target="_blank"><strong>WinHDD</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.CheckDisk" target="_blank"><strong>CheckDisk</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.UltraDefragger" target="_blank"><strong>Ultra Defragger</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.QuickDefragmenter" target="_blank"><strong>Quick Defragmenter</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartDefragmenter" target="_blank"><strong>Smart Defragmenter</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDDefragmenter" target="_blank"><strong>HDD Defragmenter</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemDefragmenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemDefragmenter" target="_blank"><strong>System Defragmenter</strong></a></li>
</ul>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\%random%</li>
<li>%AllUsersProfile%\Application Data\%random%.exe</li>
<li>%AllUsersProfile%\Application Data\%random%.exe</li>
<li>%UserProfile%\Desktop\Windows Repair.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Windows Repair\</li>
<li>%UserProfile%\Start Menu\Programs\Windows Repair\Uninstall Windows Repair.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Windows Repair\Windows Repair.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\<br />
DisableTaskMgr: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\<br />
75fa38b7-8b94-4995-ad32-52e938867954:<br />
BD: 43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 74 00 73 00 20 00 61 00…</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\<br />
Use FormSuggest: “Yes”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\<br />
WarnonBadCertRecving: 0×00000000<br />
CertificateRevocation: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\<br />
NoChangingWallPaper: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\<br />
LowRiskFileTypes:   “/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\<br />
SaveZoneInformation: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\<br />
DisableTaskMgr: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
%random%: “%AllUsersProfile%\Application Data\%random%.exe”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures: “no”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
Hidden: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
ShowSuperHidden: 0×00000000</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRepair_1.png"><img class="alignnone size-medium wp-image-1967" title="Adware.Win32.WindowsRepair" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRepair_1-400x104.png" alt="" width="400" height="104" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRepair_2.png"><img class="alignnone size-medium wp-image-1968" title="Adware.Win32.WindowsRepair" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRepair_2-400x79.png" alt="" width="400" height="79" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRepair_3.png"><img class="alignnone size-medium wp-image-1969" title="Adware.Win32.WindowsRepair" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRepair_3-400x268.png" alt="" width="400" height="268" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRepair_4.png"><img class="alignnone size-medium wp-image-1970" title="Adware.Win32.WindowsRepair" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRepair_4-400x268.png" alt="" width="400" height="268" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRepair_5.png"><img class="alignnone size-medium wp-image-1971" title="Adware.Win32.WindowsRepair" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRepair_5-400x268.png" alt="" width="400" height="268" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRepair_6.png"><img class="alignnone size-medium wp-image-1972" title="Adware.Win32.WindowsRepair" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRepair_6-400x268.png" alt="" width="400" height="268" /></a></strong></p>
<p><strong>How to remove the infection of </strong><strong>Windows Repair </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRepair" target="_blank">Adware.Win32.WindowsRepair</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/04/08/windows-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/05/17/windows-xp-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">Win XP Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/04/05/windows-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/08/disk-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">Disk Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/04/windows-disk-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Disk Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/04/05/windows-repair-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Recovery Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/04/05/windows-recovery-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/04/05/windows-recovery-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 05 Apr 2011 08:04:41 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Recovery]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=1959</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Recovery adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsRecovery. Windows Recovery is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with viruses or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Recovery </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRecovery" target="_blank"><strong>Adware.Win32.WindowsRecovery</strong></a><strong>.</strong></p>
<p><strong>Windows Recovery </strong>is a rogue    application.                                    A  rogue   application  tries    to trick  you  by                  displaying         false               positive/misleading        scan       results         report,  which    says        that  your                   computer    has a    problem,      or     infected with          viruses    or       trojan,      but   you      will    not   be    able          to fix it        before you           purchase.</p>
<p><strong>Variants of the rogue defragmenter:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDiagnostic" target="_blank"><strong>Windows Diagnostic</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinScan" target="_blank"><strong>Win Scan</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinDisk" target="_blank"><strong>Win Disk</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DiskRecovery" target="_blank"><strong>Disk Recovery</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDisk" target="_blank"><strong>Windows Disk</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsScan" target="_blank"><strong>Windows Scan</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MemoryOptimizer" target="_blank"><strong>Memory Optimizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DiskOptimizer" target="_blank"><strong>Disk Optimizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.EasyScan" target="_blank"><strong>Easy Scan</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GoodMemory" target="_blank"><strong>Good Memory</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.FastDisk" target="_blank"><strong>Fast Disk</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DiskOK" target="_blank"><strong>Disk OK</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MyDisk" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MyDisk" target="_blank"><strong>My Disk</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MemoryFixer" target="_blank"><strong>Memory Fixer</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDFix" target="_blank">HDD Fix</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DefragScanner" target="_blank"><strong>Scanner</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDLow" target="_blank"><strong>HDD Low</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DiskRepair" target="_blank"><strong>Disk Repair</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.Defragmenter" target="_blank"><strong>Defragmenter</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDTools" target="_blank"><strong>HDD Tools</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartHDD" target="_blank"><strong>Smart HDD</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDRescue" target="_blank"><strong>HDD Rescue</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDPlus" target="_blank"><strong>HDD Plus</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDDiagnostic" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDDiagnostic" target="_blank"><strong>HDD Diagnostic</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HardDriveDiagnostic" target="_blank"><strong>Hard Drive Diagnostic</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DiskDoctor" target="_blank"><strong>Disk Doctor</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinDefragmenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinDefragmenter" target="_blank"><strong>Win Defragmenter</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinDefrag" target="_blank"><strong>WinDefrag</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WinHDD" target="_blank"><strong>WinHDD</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.CheckDisk" target="_blank"><strong>CheckDisk</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.UltraDefragger" target="_blank"><strong>Ultra Defragger</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.QuickDefragmenter" target="_blank"><strong>Quick Defragmenter</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartDefragmenter" target="_blank"><strong>Smart Defragmenter</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDDefragmenter" target="_blank"><strong>HDD Defragmenter</strong></a><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemDefragmenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemDefragmenter" target="_blank"><strong>System Defragmenter</strong></a></li>
</ul>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\%random%</li>
<li>%AllUsersProfile%\Application Data\%random%.exe</li>
<li>%AllUsersProfile%\Application Data\%random%.exe</li>
<li>%AllUsersProfile%\Application Data\~%random%</li>
<li>%AllUsersProfile%\Application Data\~%random%r</li>
<li>%UserProfile%\Desktop\Windows Recovery.lnk</li>
<li>%UserProfile%\Local Settings\Temp\%random%.tmp</li>
<li>%UserProfile%\Local Settings\Temp\%random%.tmp</li>
<li>%UserProfile%\Start Menu\Programs\Windows Recovery\</li>
<li>%UserProfile%\Start Menu\Programs\Windows Recovery\Uninstall Windows Recovery.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Windows Recovery\Windows Recovery.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\<br />
DisableTaskMgr: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\<br />
75fa38b7-8b94-4995-ad32-52e938867954:<br />
BD: 43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 74 00 73 00 20 00 61 00…</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\<br />
Use FormSuggest: “Yes”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\<br />
WarnonBadCertRecving: 0×00000000<br />
CertificateRevocation: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\<br />
NoChangingWallPaper: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\<br />
LowRiskFileTypes:  “/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\<br />
SaveZoneInformation: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\<br />
DisableTaskMgr: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
EAGueaRwrDlOoPP: “%AllUsersProfile%\Application Data\EAGueaRwrDlOoPP.exe”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures: “no”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
Hidden: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
ShowSuperHidden: 0×00000000</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRecovery_1.png"><img class="alignnone size-medium wp-image-1960" title="Adware.Win32.WindowsRecovery" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRecovery_1-400x268.png" alt="" width="400" height="268" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRecovery_2.png"><img class="alignnone size-medium wp-image-1961" title="Adware.Win32.WindowsRecovery" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRecovery_2-400x268.png" alt="" width="400" height="268" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRecovery_3.png"><img class="alignnone size-medium wp-image-1962" title="Adware.Win32.WindowsRecovery" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRecovery_3-400x268.png" alt="" width="400" height="268" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRecovery_4.png"><img class="alignnone size-medium wp-image-1963" title="Adware.Win32.WindowsRecovery" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsRecovery_4-400x268.png" alt="" width="400" height="268" /></a></strong></p>
<p><strong>How to remove the infection of </strong><strong>Windows Recovery </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRecovery" target="_blank">Adware.Win32.WindowsRecovery</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/05/17/windows-xp-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">Win XP Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/04/08/windows-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/08/disk-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">Disk Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/04/05/windows-repair-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Repair Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/16/windows-diagnostic-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Diagnostic Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/04/05/windows-recovery-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Simple Protector Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/04/05/windows-simple-protector-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/04/05/windows-simple-protector-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 05 Apr 2011 05:47:37 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Simple Protector]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=1948</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Simple Protector adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsSimpleProtector. Windows Simple Protector is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Simple Protector </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>Adware.Win32.WindowsSimpleProtector</strong></a><strong>.</strong></p>
<p><strong>Windows Simple Protector</strong><strong> </strong>is a         rogue           application.                                   A    rogue                application  tries    to trick you  by                      displaying                    false               positive/misleading           scan             results               report,  which   says           that  your                             computer      has a     problem,       or     infected  with                   viruses    or          trojan,        but  you       will      not      be        able           to  fix   it         before you               purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Windows Stability Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a>,</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong>.</li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsSimpleProtector_1.png"><img class="alignnone size-medium wp-image-1949" title="Adware.Win32.WindowsSimpleProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsSimpleProtector_1-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsSimpleProtector_2.png"><img class="alignnone size-medium wp-image-1950" title="Adware.Win32.WindowsSimpleProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsSimpleProtector_2-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsSimpleProtector_3.png"><img class="alignnone size-medium wp-image-1951" title="Adware.Win32.WindowsSimpleProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsSimpleProtector_3-400x228.png" alt="" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsSimpleProtector_4.png"><img class="alignnone size-medium wp-image-1952" title="Adware.Win32.WindowsSimpleProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsSimpleProtector_4-400x228.png" alt="" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsSimpleProtector_5.png"><img class="alignnone size-full wp-image-1953" title="Adware.Win32.WindowsSimpleProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsSimpleProtector_5.png" alt="" width="396" height="254" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsSimpleProtector_6.png"><img class="alignnone size-medium wp-image-1954" title="Adware.Win32.WindowsSimpleProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsSimpleProtector_6-400x270.png" alt="" width="400" height="270" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsSimpleProtector_7.png"><img class="alignnone size-medium wp-image-1955" title="Adware.Win32.WindowsSimpleProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsSimpleProtector_7-400x270.png" alt="" width="400" height="270" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsSimpleProtector_8.png"><img class="alignnone size-medium wp-image-1956" title="Adware.Win32.WindowsSimpleProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsSimpleProtector_8-400x270.png" alt="" width="400" height="270" /></a></strong></p>
<p><strong>How to remove the infection of Windows Simple Protector</strong><strong> </strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank">Adware.Win32.</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSimpleProtector" target="_blank"><strong>WindowsSimpleProtector</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/04/01/windows-stability-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Stability Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-defence-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Defence Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/04/05/windows-simple-protector-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Stability Center Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/04/01/windows-stability-center-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/04/01/windows-stability-center-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 01 Apr 2011 10:03:50 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Stability Center]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=1938</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Stability Center adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsStabilityCenter. Windows Stability Center is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Stability Center </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank"><strong>Adware.Win32.</strong><strong>WindowsStabilityCenter</strong></a><strong>.</strong></p>
<p><strong>Windows Stability Center</strong><strong> </strong>is a        rogue           application.                                   A   rogue                application  tries    to trick you  by                     displaying                    false              positive/misleading           scan             results              report,  which   says           that  your                            computer      has a     problem,       or     infected  with                  viruses    or          trojan,        but  you       will      not     be        able           to  fix   it         before you              purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Windows Power Expansion</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a>,</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong>.</li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsStabilityCenter_1.png"><img class="alignnone size-medium wp-image-1939" title="Adware.Win32.WindowsStabilityCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsStabilityCenter_1-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsStabilityCenter_2.png"><img class="alignnone size-medium wp-image-1940" title="Adware.Win32.WindowsStabilityCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsStabilityCenter_2-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsStabilityCenter_3.png"><img class="alignnone size-medium wp-image-1941" title="Adware.Win32.WindowsStabilityCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsStabilityCenter_3-400x228.png" alt="" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsStabilityCenter_4.png"><img class="alignnone size-full wp-image-1942" title="Adware.Win32.WindowsStabilityCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsStabilityCenter_4.png" alt="" width="396" height="254" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsStabilityCenter_5.png"><img class="alignnone size-medium wp-image-1943" title="Adware.Win32.WindowsStabilityCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsStabilityCenter_5-400x270.png" alt="" width="400" height="270" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsStabilityCenter_6.png"><img class="alignnone size-medium wp-image-1944" title="Adware.Win32.WindowsStabilityCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsStabilityCenter_6-400x270.png" alt="" width="400" height="270" /></a></strong></p>
<p><strong>How to remove the infection of Windows Stability Center</strong><strong> </strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityCenter" target="_blank">Adware.Win32.WindowsStabilityCenter</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-defence-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Defence Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/16/windows-remedy-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Remedy Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/04/01/windows-stability-center-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Power Expansion Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/04/01/windows-power-expansion-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/04/01/windows-power-expansion-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 01 Apr 2011 09:57:29 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Power Expansion]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=1929</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Power Expansion adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsPowerExpansion. Windows Power Expansion is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Power Expansion </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>Adware.Win32.</strong><strong>WindowsPowerExpansion</strong></a><strong>.</strong></p>
<p><strong>Windows Power Expansion</strong><strong> </strong>is a       rogue           application.                                   A   rogue               application  tries    to trick you  by                    displaying                    false              positive/misleading          scan             results              report,  which   says          that  your                            computer      has a    problem,       or     infected  with                  viruses    or         trojan,        but  you       will      not     be        able          to  fix   it         before you              purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Windows Expansion System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a>,</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong>.</li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPowerExpansion_1.png"><img class="alignnone size-medium wp-image-1930" title="Adware.Win32.WindowsPowerExpansion" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPowerExpansion_1-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPowerExpansion_2.png"><img class="alignnone size-medium wp-image-1931" title="Adware.Win32.WindowsPowerExpansion" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPowerExpansion_2-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPowerExpansion_3.png"><img class="alignnone size-medium wp-image-1932" title="Adware.Win32.WindowsPowerExpansion" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPowerExpansion_3-400x228.png" alt="" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPowerExpansion_4.png"><img class="alignnone size-medium wp-image-1933" title="Adware.Win32.WindowsPowerExpansion" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPowerExpansion_4-400x228.png" alt="" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPowerExpansion_5.png"><img class="alignnone size-full wp-image-1934" title="Adware.Win32.WindowsPowerExpansion" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPowerExpansion_5.png" alt="" width="396" height="254" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPowerExpansion_6.png"><img class="alignnone size-medium wp-image-1935" title="Adware.Win32.WindowsPowerExpansion" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPowerExpansion_6-400x270.png" alt="" width="400" height="270" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPowerExpansion_7.png"><img class="alignnone size-medium wp-image-1936" title="Adware.Win32.WindowsPowerExpansion" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsPowerExpansion_7-400x270.png" alt="" width="400" height="270" /></a></strong></p>
<p><strong>How to remove the infection of Windows Power Expansion</strong><strong> </strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank">Adware.Win32.</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPowerExpansion" target="_blank"><strong>WindowsPowerExpansion</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/04/01/windows-stability-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Stability Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/04/01/windows-expansion-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Expansion System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/04/01/windows-power-expansion-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Expansion System Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/04/01/windows-expansion-system-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/04/01/windows-expansion-system-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 01 Apr 2011 09:45:26 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Expansion System]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=1919</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Expansion System adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsExpansionSystem. Windows Expansion System is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Expansion System </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank"><strong>Adware.Win32.WindowsExpansionSystem</strong></a><strong>.</strong></p>
<p><strong>Windows Expansion System</strong><strong> </strong>is a      rogue           application.                                   A   rogue              application  tries    to trick you  by                   displaying                    false              positive/misleading         scan             results              report,  which   says         that  your                            computer      has a    problem,      or     infected  with                  viruses    or         trojan,       but  you       will      not     be        able          to  fix  it         before you              purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Windows Background Protector</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a>,</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong> </strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong>.</li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsExpansionSystem_1.png"><img class="alignnone size-medium wp-image-1920" title="Adware.Win32.WindowsExpansionSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsExpansionSystem_1-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsExpansionSystem_2.png"><img class="alignnone size-medium wp-image-1921" title="Adware.Win32.WindowsExpansionSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsExpansionSystem_2-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsExpansionSystem_3.png"><img class="alignnone size-medium wp-image-1922" title="Adware.Win32.WindowsExpansionSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsExpansionSystem_3-400x228.png" alt="" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsExpansionSystem_4.png"><img class="alignnone size-medium wp-image-1923" title="Adware.Win32.WindowsExpansionSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsExpansionSystem_4-400x228.png" alt="" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsExpansionSystem_5.png"><img class="alignnone size-full wp-image-1924" title="Adware.Win32.WindowsExpansionSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsExpansionSystem_5.png" alt="" width="396" height="254" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsExpansionSystem_6.png"><img class="alignnone size-medium wp-image-1925" title="Adware.Win32.WindowsExpansionSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsExpansionSystem_6-400x270.png" alt="" width="400" height="270" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsExpansionSystem_7.png"><img class="alignnone size-medium wp-image-1926" title="Adware.Win32.WindowsExpansionSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/04/Adware.Win32.WindowsExpansionSystem_7-400x270.png" alt="" width="400" height="270" /></a></strong></p>
<p><strong>How to remove the infection of Windows Expansion System</strong><strong> </strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpansionSystem" target="_blank">Adware.Win32.WindowsExpansionSystem</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/04/01/windows-stability-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Stability Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/04/01/windows-power-expansion-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Power Expansion Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/04/01/windows-expansion-system-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Background Protector Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/03/25/windows-background-protector-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/03/25/windows-background-protector-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 25 Mar 2011 14:06:09 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Background Protector]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=1910</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Background Protector adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsBackgroundProtector. Windows Background Protector is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Background Protector </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>Adware.Win32.WindowsBackgroundProtector</strong></a><strong>.</strong></p>
<p><strong>Windows Background Protector</strong><strong> </strong>is a     rogue           application.                                   A  rogue              application  tries    to trick you  by                  displaying                    false              positive/misleading        scan             results              report,  which   says        that  your                            computer      has a    problem,     or     infected  with                  viruses    or         trojan,      but  you       will      not     be        able          to  fix it         before you              purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Windows Lowlevel Solution</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a>,</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong>.</li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsBackgroundProtector_1.png"><img class="alignnone size-medium wp-image-1911" title="Adware.Win32.WindowsBackgroundProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsBackgroundProtector_1-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsBackgroundProtector_2.png"><img class="alignnone size-medium wp-image-1912" title="Adware.Win32.WindowsBackgroundProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsBackgroundProtector_2-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsBackgroundProtector_3.png"><img class="alignnone size-medium wp-image-1913" title="Adware.Win32.WindowsBackgroundProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsBackgroundProtector_3-400x228.png" alt="" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsBackgroundProtector_4.png"><img class="alignnone size-medium wp-image-1914" title="Adware.Win32.WindowsBackgroundProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsBackgroundProtector_4-400x228.png" alt="" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsBackgroundProtector_5.png"><img class="alignnone size-full wp-image-1915" title="Adware.Win32.WindowsBackgroundProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsBackgroundProtector_5.png" alt="" width="396" height="254" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsBackgroundProtector_6.png"><img class="alignnone size-medium wp-image-1916" title="Adware.Win32.WindowsBackgroundProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsBackgroundProtector_6-400x270.png" alt="" width="400" height="270" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsBackgroundProtector_7.png"><img class="alignnone size-medium wp-image-1917" title="Adware.Win32.WindowsBackgroundProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsBackgroundProtector_7-400x270.png" alt="" width="400" height="270" /></a></strong></p>
<p><strong>How to remove the infection of Windows Background Protector</strong><strong> </strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank">Adware.Win32.</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBackgroundProtector" target="_blank"><strong>WindowsBackgroundProtector</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/04/01/windows-stability-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Stability Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/04/01/windows-expansion-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Expansion System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/03/25/windows-background-protector-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Lowlevel Solution Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/03/25/windows-lowlevel-solution-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/03/25/windows-lowlevel-solution-adware-removal-instructions/#comments</comments>
		<pubDate>Fri, 25 Mar 2011 13:56:19 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Lowlevel Solution]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=1900</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Lowlevel Solution adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsLowlevelSolution. Windows Lowlevel Solution is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Lowlevel Solution </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>Adware.Win32.WindowsLowlevelSolution</strong></a><strong>.</strong></p>
<p><strong>Windows Lowlevel Solution </strong>is a     rogue          application.                                   A  rogue             application  tries    to trick you  by                  displaying                   false              positive/misleading        scan            results              report,  which   says        that  your                           computer      has a    problem,     or     infected with                  viruses    or         trojan,      but  you      will      not     be        able          to  fix it         before you             purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Windows Support System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a>,</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong>.</li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsLowLevelSolution_1.png"><img class="alignnone size-medium wp-image-1901" title="Adware.Win32.WindowsLowLevelSolution" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsLowLevelSolution_1-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsLowLevelSolution_2.png"><img class="alignnone size-medium wp-image-1902" title="Adware.Win32.WindowsLowLevelSolution" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsLowLevelSolution_2-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsLowLevelSolution_3.png"><img class="alignnone size-medium wp-image-1903" title="Adware.Win32.WindowsLowLevelSolution" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsLowLevelSolution_3-400x228.png" alt="" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsLowLevelSolution_4.png"><img class="alignnone size-medium wp-image-1904" title="Adware.Win32.WindowsLowLevelSolution" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsLowLevelSolution_4-400x228.png" alt="" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsLowLevelSolution_5.png"><img class="alignnone size-full wp-image-1905" title="Adware.Win32.WindowsLowLevelSolution" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsLowLevelSolution_5.png" alt="" width="396" height="254" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsLowLevelSolution_6.png"><img class="alignnone size-medium wp-image-1906" title="Adware.Win32.WindowsLowLevelSolution" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsLowLevelSolution_6-400x270.png" alt="" width="400" height="270" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsLowLevelSolution_7.png"><img class="alignnone size-medium wp-image-1907" title="Adware.Win32.WindowsLowLevelSolution" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsLowLevelSolution_7-400x270.png" alt="" width="400" height="270" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsLowLevelSolution_8.png"><img class="alignnone size-medium wp-image-1908" title="Adware.Win32.WindowsLowLevelSolution" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsLowLevelSolution_8-400x270.png" alt="" width="400" height="270" /></a></strong></p>
<p><strong>How to remove the infection of Windows Lowlevel Solution</strong><strong> </strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank">Adware.Win32.</a></strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsLowlevelSolution" target="_blank"><strong>WindowsLowlevelSolution</strong></a><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/25/windows-background-protector-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Background Protector Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-defence-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Defence Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/03/25/windows-lowlevel-solution-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Support System Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/03/22/windows-support-system-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/03/22/windows-support-system-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 22 Mar 2011 07:36:23 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Support System]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=1891</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Support System adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsSupport System. Windows Support System is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Support System </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank"><strong>Adware.Win32.WindowsSupport System</strong></a><strong>.</strong></p>
<p><strong>Windows Support System </strong>is a     rogue         application.                                   A  rogue            application  tries    to trick you  by                  displaying                  false              positive/misleading        scan           results              report,  which   says        that  your                          computer      has a    problem,     or     infected with                 viruses    or         trojan,      but  you      will     not     be        able          to  fix it         before you            purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Windows Emergency System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a>,</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong>.</li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsSupportSystem_1.png"><img class="alignnone size-medium wp-image-1892" title="Adware.Win32.WindowsSupportSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsSupportSystem_1-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsSupportSystem_2.png"><img class="alignnone size-medium wp-image-1893" title="Adware.Win32.WindowsSupportSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsSupportSystem_2-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsSupportSystem_3.png"><img class="alignnone size-medium wp-image-1894" title="Adware.Win32.WindowsSupportSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsSupportSystem_3-400x228.png" alt="" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsSupportSystem_4.png"><img class="alignnone size-medium wp-image-1895" title="Adware.Win32.WindowsSupportSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsSupportSystem_4-400x228.png" alt="" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsSupportSystem_5.png"><img class="alignnone size-full wp-image-1896" title="Adware.Win32.WindowsSupportSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsSupportSystem_5.png" alt="" width="396" height="254" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsSupportSystem_6.png"><img class="alignnone size-medium wp-image-1897" title="Adware.Win32.WindowsSupportSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsSupportSystem_6-400x270.png" alt="" width="400" height="270" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsSupportSystem_7.png"><img class="alignnone size-medium wp-image-1898" title="Adware.Win32.WindowsSupportSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsSupportSystem_7-400x257.png" alt="" width="400" height="257" /></a></strong></p>
<p><strong>How to remove the infection of Windows Support System</strong><strong> </strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSupportSystem" target="_blank">Adware.Win32.WindowsSupportSystem</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/16/windows-remedy-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Remedy Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/19/windows-emergency-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Emergency System Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/03/22/windows-support-system-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Emergency System Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/03/19/windows-emergency-system-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/03/19/windows-emergency-system-adware-removal-instructions/#comments</comments>
		<pubDate>Sat, 19 Mar 2011 09:51:37 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Emergency System]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=1882</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Emergency System adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsEmergencySystem. Windows Emergency System is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Emergency System </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank"><strong>Adware.Win32.WindowsEmergencySystem</strong></a><strong>.</strong></p>
<p><strong>Windows Emergency System </strong>is a     rogue        application.                                   A  rogue           application  tries    to trick you  by                  displaying                 false              positive/misleading        scan          results              report,  which   says        that  your                         computer      has a    problem,     or     infected with                viruses    or         trojan,      but  you      will    not     be        able          to  fix it         before you           purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Windows Threats Removing</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a>,</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong>.</li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsEmergencySystem_1.png"><img class="alignnone size-medium wp-image-1883" title="Adware.Win32.WindowsEmergencySystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsEmergencySystem_1-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsEmergencySystem_2.png"><img class="alignnone size-medium wp-image-1884" title="Adware.Win32.WindowsEmergencySystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsEmergencySystem_2-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsEmergencySystem_3.png"><img class="alignnone size-medium wp-image-1885" title="Adware.Win32.WindowsEmergencySystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsEmergencySystem_3-400x228.png" alt="" width="400" height="228" /><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsEmergencySystem_4.png"></a></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsEmergencySystem_3.png"><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsEmergencySystem_4.png"><img class="alignnone size-medium wp-image-1886" title="Adware.Win32.WindowsEmergencySystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsEmergencySystem_4-400x228.png" alt="" width="400" height="228" /></a></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsEmergencySystem_5.png"><img class="alignnone size-full wp-image-1887" title="Adware.Win32.WindowsEmergencySystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsEmergencySystem_5.png" alt="" width="396" height="254" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsEmergencySystem_6.png"><img class="alignnone size-medium wp-image-1888" title="Adware.Win32.WindowsEmergencySystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsEmergencySystem_6-400x270.png" alt="" width="400" height="270" /></a></strong></p>
<p><strong>How to remove the infection of Windows Emergency System</strong><strong> </strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEmergencySystem" target="_blank">Adware.Win32.WindowsEmergencySystem</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-servant-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Servant System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/16/windows-remedy-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Remedy Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-defence-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Defence Center Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/03/19/windows-emergency-system-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Threats Removing Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/03/19/windows-threats-removing-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/03/19/windows-threats-removing-adware-removal-instructions/#comments</comments>
		<pubDate>Sat, 19 Mar 2011 09:44:42 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Threats Removing]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=1873</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Threats Removing adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsThreatsRemoving. Windows Threats Removing is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Threats Removing </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank"><strong>Adware.Win32.WindowsThreatsRemoving</strong></a><strong>.</strong></p>
<p><strong>Windows Threats Removing </strong>is a     rogue       application.                                   A  rogue          application  tries    to trick you  by                  displaying                false              positive/misleading        scan         results              report,  which   says        that  your                        computer      has a    problem,     or     infected with               viruses    or         trojan,      but  you      will    not    be        able          to  fix it         before you          purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Windows Remedy</a><br />
</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a>,</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong>.</li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsThreatsRemoving_1.png"><img class="alignnone size-medium wp-image-1874" title="Adware.Win32.WindowsThreatsRemoving" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsThreatsRemoving_1-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsThreatsRemoving_2.png"><img class="alignnone size-medium wp-image-1875" title="Adware.Win32.WindowsThreatsRemoving" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsThreatsRemoving_2-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsThreatsRemoving_3.png"><img class="alignnone size-medium wp-image-1876" title="Adware.Win32.WindowsThreatsRemoving" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsThreatsRemoving_3-400x228.png" alt="" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsThreatsRemoving_4.png"><img class="alignnone size-medium wp-image-1877" title="Adware.Win32.WindowsThreatsRemoving" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsThreatsRemoving_4-400x228.png" alt="" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsThreatsRemoving_5.png"><img class="alignnone size-full wp-image-1878" title="Adware.Win32.WindowsThreatsRemoving" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsThreatsRemoving_5.png" alt="" width="396" height="254" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsThreatsRemoving_6.png"><img class="alignnone size-medium wp-image-1879" title="Adware.Win32.WindowsThreatsRemoving" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsThreatsRemoving_6-400x270.png" alt="" width="400" height="270" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsThreatsRemoving_7.png"><img class="alignnone size-medium wp-image-1880" title="Adware.Win32.WindowsThreatsRemoving" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsThreatsRemoving_7-400x270.png" alt="" width="400" height="270" /></a></strong></p>
<p><strong>How to remove the infection of Windows Threats Removing</strong><strong> </strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsRemoving" target="_blank">Adware.Win32.WindowsThreatsRemoving</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/19/windows-emergency-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Emergency System Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-defence-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Defence Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/03/19/windows-threats-removing-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Remedy Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/03/16/windows-remedy-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/03/16/windows-remedy-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 16 Mar 2011 06:11:08 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Remedy]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=1864</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Remedy adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsRemedy. Windows Remedy is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with viruses or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Windows Remedy </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank"><strong>Adware.Win32.</strong><strong>WindowsRemedy</strong></a><strong>.</strong></p>
<p><strong>Windows Remedy</strong><strong> </strong>is a     rogue      application.                                   A  rogue         application  tries    to trick you  by                  displaying               false              positive/misleading        scan        results              report,  which   says        that  your                       computer      has a    problem,     or     infected with              viruses    or         trojan,      but  you      will    not   be        able          to  fix it         before you          purchase.</p>
<p><strong>Another variants:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesRemover" target="_blank"><strong>Windows Troubles Remover</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublemakersAgent" target="_blank"><strong>Windows Troublemakers Agent</strong></a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsServantSystem" target="_blank"><strong>Windows Servant System</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefenceCenter" target="_blank"><strong>Windows Defence Center</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsErrorCorrection" target="_blank"><strong>Windows Error Correction</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceManager" target="_blank"><strong>Windows Performance Manager</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroublesAnalyzer" target="_blank"><strong>Windows Troubles Analyzer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessesOrganizer" target="_blank"><strong>Windows Processes Organizer</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalTool" target="_blank"><strong>Windows Optimal Tool</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressSettings" target="_blank"><strong>Windows Express Settings</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyGuarantee" target="_blank"><strong>Windows Safety Guarantee</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsExpressHelp" target="_blank">Windows Express Help</a>,</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAVSoftware" target="_blank"><strong>Windows AV Software</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUserSatellite" target="_blank">Windows User Satellite</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsSolution" target="_blank">Windows Problems Solution</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSettings" target="_blank"><strong>Windows Optimal Settings</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimalSolution" target="_blank"><strong>Windows Optimal Solution</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTool" target="_blank">Windows Care Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareGuard" target="_blank">Windows Software Guard</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWiseProtection" target="_blank">Windows Wise Protection</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareProtection" target="_blank">Windows Software Protection</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsProtector" target="_blank">Windows Problems Protector</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldCenter" target="_blank">Windows Shield Center</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsRemover">Windows Problems Remover</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsHealthCenter" target="_blank"><strong>Windows Health Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntispywareSolution" target="_blank">Windows Antispyware Solution</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUniversalTools" target="_blank">Windows Universal Tools</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskEliminator" target="_blank">Windows Risk Eliminator</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecurityControl" target="_blank">Windows Security &amp; Control</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsUtilityTool" target="_blank">Windows Utility Tool</a>,</strong> <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationSecurity" target="_blank">Windows Optimization &amp; Security</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsOptimizationCenter" target="_blank"><strong>Windows Optimization Center</strong></a>, <strong></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyGuard2010" target="_blank">Privacy Guard 2010</a></strong>.</li>
</ul>
<p><strong>Create new file:</strong></p>
<ul>
<li>%UserProfile%\Application Data\Microsoft\%random%.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon<br />
(String) Shell = %UserProfile%\Application Data\Microsoft\%random%.exe</li>
<li>HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\SystemRestore<br />
(DWORD) DisableSR = 0×00000001 (1)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\System<br />
(DWORD) EnableLUA = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorAdmin = 0×00000000 (0)<br />
(DWORD) ConsentPromptBehaviorUser = 0×00000000 (0)</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\afwserv.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastsvc.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\avastui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\egui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\ekrn.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msascui.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msmpeng.exe<br />
(String) Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\Image File Execution Options\msseces.exe<br />
(String) Debugger = svchost.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsRemedy_1.png"><img class="alignnone size-medium wp-image-1865" title="Adware.Win32.WindowsRemedy" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsRemedy_1-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsRemedy_2.png"><img class="alignnone size-medium wp-image-1866" title="Adware.Win32.WindowsRemedy" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsRemedy_2-400x208.png" alt="" width="400" height="208" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsRemedy_3.png"><img class="alignnone size-medium wp-image-1867" title="Adware.Win32.WindowsRemedy" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsRemedy_3-400x228.png" alt="" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsRemedy_4.png"><img class="alignnone size-medium wp-image-1868" title="Adware.Win32.WindowsRemedy" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsRemedy_4-400x228.png" alt="" width="400" height="228" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsRemedy_5.png"><img class="alignnone size-full wp-image-1869" title="Adware.Win32.WindowsRemedy" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsRemedy_5.png" alt="" width="396" height="254" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsRemedy_6.png"><img class="alignnone size-medium wp-image-1870" title="Adware.Win32.WindowsRemedy" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/03/Adware.Win32.WindowsRemedy_6-400x270.png" alt="" width="400" height="270" /></a></strong></p>
<p><strong>How to remove the infection of Windows Remedy</strong><strong> </strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRemedy" target="_blank">Adware.Win32.WindowsRemedy</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/03/03/windows-performance-manager-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Manager Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/01/windows-troubles-analyzer-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Analyzer Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/11/windows-defence-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Defence Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/14/windows-troubles-remover-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Troubles Remover Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/03/19/windows-emergency-system-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Emergency System Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/03/16/windows-remedy-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

