<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Emsisoft New Malware Blog</title>
	<atom:link href="http://www.anti-malware-blog.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.anti-malware-blog.com</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Fri, 18 May 2012 11:54:49 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Windows Pro Safety Release Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/18/windows-pro-safety-release-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/18/windows-pro-safety-release-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 18 May 2012 11:54:22 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Pro Safety Release]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3447</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Pro Safety Release. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsProSafetyRelease. Windows Pro Safety Release is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Pro Safety Release</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsProSafetyRelease" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProSafetyRelease" target="_blank"><strong>Rogue.Win32.WindowsProSafetyRelease</strong></a><strong>.</strong></p>
<p><strong>Windows Pro Safety Release</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Pro Safety Release.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Pro Safety Release.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSafetyRelease_1.png"><img class="alignnone size-medium wp-image-3448" title="Rogue.Win32.WindowsProSafetyRelease" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSafetyRelease_1-400x234.png" alt="Rogue.Win32.WindowsProSafetyRelease" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSafetyRelease_2.png"><img class="alignnone size-medium wp-image-3449" title="Rogue.Win32.WindowsProSafetyRelease" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSafetyRelease_2-400x293.png" alt="Rogue.Win32.WindowsProSafetyRelease" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSafetyRelease_3.png"><img class="alignnone size-medium wp-image-3450" title="Rogue.Win32.WindowsProSafetyRelease" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSafetyRelease_3-400x293.png" alt="Rogue.Win32.WindowsProSafetyRelease" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSafetyRelease_4.png"><img class="alignnone size-medium wp-image-3451" title="Rogue.Win32.WindowsProSafetyRelease" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSafetyRelease_4-400x238.png" alt="Rogue.Win32.WindowsProSafetyRelease" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSafetyRelease_5.png"><img class="alignnone size-medium wp-image-3452" title="Rogue.Win32.WindowsProSafetyRelease" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSafetyRelease_5-400x253.png" alt="Rogue.Win32.WindowsProSafetyRelease" width="400" height="253" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSafetyRelease_6.png"><img class="alignnone size-medium wp-image-3453" title="Rogue.Win32.WindowsProSafetyRelease" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSafetyRelease_6-400x293.png" alt="Rogue.Win32.WindowsProSafetyRelease" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong>Windows Pro Safety Release</strong> </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProSafetyRelease" target="_blank">Rogue.Win32.WindowsProSafetyRelease</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Safety Toolkit Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Safety Checkpoint Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-safety-manager-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Safety Manager Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/18/windows-pro-safety-release-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Safeguard Upgrade Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/17/windows-safeguard-upgrade-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/17/windows-safeguard-upgrade-rogue-removal-instructions/#comments</comments>
		<pubDate>Thu, 17 May 2012 09:38:08 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Safeguard Upgrade]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3438</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Safeguard Upgrade. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsSafeguardUpgrade. Windows Safeguard Upgrade is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Safeguard Upgrade</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsSafeguardUpgrade" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUpgrade" target="_blank"><strong>Rogue.Win32.WindowsSafeguardUpgrade</strong></a><strong>.</strong></p>
<p><strong><strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong></strong><strong><strong><strong><strong>Windows Safeguard Upgrade</strong></strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Safeguard Upgrade.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Safeguard Upgrade.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSafeguardUpgrade_1.png"><img class="alignnone size-medium wp-image-3439" title="Rogue.Win32.WindowsSafeguardUpgrade" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSafeguardUpgrade_1-400x234.png" alt="Rogue.Win32.WindowsSafeguardUpgrade" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSafeguardUpgrade_2.png"><img class="alignnone size-medium wp-image-3440" title="Rogue.Win32.WindowsSafeguardUpgrade" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSafeguardUpgrade_2-400x293.png" alt="Rogue.Win32.WindowsSafeguardUpgrade" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSafeguardUpgrade_3.png"><img class="alignnone size-medium wp-image-3441" title="Rogue.Win32.WindowsSafeguardUpgrade" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSafeguardUpgrade_3-400x293.png" alt="Rogue.Win32.WindowsSafeguardUpgrade" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSafeguardUpgrade_4.png"><img class="alignnone size-medium wp-image-3442" title="Rogue.Win32.WindowsSafeguardUpgrade" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSafeguardUpgrade_4-400x238.png" alt="Rogue.Win32.WindowsSafeguardUpgrade" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSafeguardUpgrade_5.png"><img class="alignnone size-medium wp-image-3443" title="Rogue.Win32.WindowsSafeguardUpgrade" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSafeguardUpgrade_5-400x253.png" alt="Rogue.Win32.WindowsSafeguardUpgrade" width="400" height="253" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSafeguardUpgrade_6.png"><img class="alignnone size-medium wp-image-3444" title="Rogue.Win32.WindowsSafeguardUpgrade" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSafeguardUpgrade_6-400x293.png" alt="Rogue.Win32.WindowsSafeguardUpgrade" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong></strong></strong></strong></strong></strong><strong><strong><strong><strong><strong><strong><strong>Windows Safeguard Upgrade</strong></strong></strong></strong> </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafeguardUpgrade" target="_blank">Rogue.Win32.WindowsSafeguardUpgrade</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows ProSecurity Scanner Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/20/windows-foolproof-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Foolproof Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/17/windows-safeguard-upgrade-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Secure Surfer Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/14/windows-secure-surfer-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/14/windows-secure-surfer-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 14 May 2012 02:21:08 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Secure Surfer]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3429</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Secure Surfer. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsSecureSurfer. Windows Secure Surfer is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Secure Surfer</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsSecureSurfer" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecureSurfer" target="_blank"><strong>Rogue.Win32.WindowsSecureSurfer</strong></a><strong>.</strong></p>
<p><strong><strong><strong><strong><strong><strong><strong>Windows Secure Surfer </strong></strong></strong></strong></strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Secure Surfer.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Secure Surfer.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSecureSurfer_1.png"><img class="alignnone size-medium wp-image-3430" title="Rogue.Win32.WindowsSecureSurfer" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSecureSurfer_1-400x234.png" alt="Rogue.Win32.WindowsSecureSurfer" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSecureSurfer_2.png"><img class="alignnone size-medium wp-image-3431" title="Rogue.Win32.WindowsSecureSurfer" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSecureSurfer_2-400x293.png" alt="Rogue.Win32.WindowsSecureSurfer" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSecureSurfer_3.png"><img class="alignnone size-medium wp-image-3432" title="Rogue.Win32.WindowsSecureSurfer" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSecureSurfer_3-400x293.png" alt="Rogue.Win32.WindowsSecureSurfer" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSecureSurfer_4.png"><img class="alignnone size-medium wp-image-3433" title="Rogue.Win32.WindowsSecureSurfer" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSecureSurfer_4-400x238.png" alt="Rogue.Win32.WindowsSecureSurfer" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSecureSurfer_5.png"><img class="alignnone size-medium wp-image-3434" title="Rogue.Win32.WindowsSecureSurfer" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSecureSurfer_5-400x253.png" alt="Rogue.Win32.WindowsSecureSurfer" width="400" height="253" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSecureSurfer_6.png"><img class="alignnone size-medium wp-image-3435" title="Rogue.Win32.WindowsSecureSurfer" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSecureSurfer_6-400x293.png" alt="Rogue.Win32.WindowsSecureSurfer" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Secure Surfer </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSecureSurfer" target="_blank">Rogue.Win32.WindowsSecureSurfer</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Debugger Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/20/windows-foolproof-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Foolproof Protector Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/14/windows-secure-surfer-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Be-on Guard Edition Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/13/windows-be-on-guard-edition-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/13/windows-be-on-guard-edition-rogue-removal-instructions/#comments</comments>
		<pubDate>Sun, 13 May 2012 03:36:59 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Be-on Guard Edition]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3421</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Be-on Guard Edition. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsBeOnGuardEdition. Windows Be-on Guard Edition is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Be-on Guard Edition</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsBeOnGuardEdition" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBeOnGuardEdition" target="_blank"><strong>Rogue.Win32.WindowsBeOnGuardEdition</strong></a><strong>.</strong></p>
<p><strong><strong><strong><strong><strong><strong><strong>Windows Be-on Guard Edition </strong></strong></strong></strong></strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Be-on-Guard Edition.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Be-on-Guard Edition.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsBeOnGuardEdition_1.png"><img class="alignnone size-medium wp-image-3422" title="Rogue.Win32.WindowsBeOnGuardEdition" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsBeOnGuardEdition_1-400x234.png" alt="Rogue.Win32.WindowsBeOnGuardEdition" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsBeOnGuardEdition_2.png"><img class="alignnone size-medium wp-image-3423" title="Rogue.Win32.WindowsBeOnGuardEdition" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsBeOnGuardEdition_2-400x293.png" alt="Rogue.Win32.WindowsBeOnGuardEdition" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsBeOnGuardEdition_3.png"><img class="alignnone size-medium wp-image-3424" title="Rogue.Win32.WindowsBeOnGuardEdition" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsBeOnGuardEdition_3-400x293.png" alt="Rogue.Win32.WindowsBeOnGuardEdition" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsBeOnGuardEdition_4.png"><img class="alignnone size-medium wp-image-3425" title="Rogue.Win32.WindowsBeOnGuardEdition" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsBeOnGuardEdition_4-400x238.png" alt="Rogue.Win32.WindowsBeOnGuardEdition" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsBeOnGuardEdition_5.png"><img class="alignnone size-medium wp-image-3426" title="Rogue.Win32.WindowsBeOnGuardEdition" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsBeOnGuardEdition_5-400x253.png" alt="Rogue.Win32.WindowsBeOnGuardEdition" width="400" height="253" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsBeOnGuardEdition_6.png"><img class="alignnone size-medium wp-image-3427" title="Rogue.Win32.WindowsBeOnGuardEdition" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsBeOnGuardEdition_6-400x293.png" alt="Rogue.Win32.WindowsBeOnGuardEdition" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Be-on Guard Edition </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsBeOnGuardEdition" target="_blank">Rogue.Win32.WindowsBeOnGuardEdition</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/26/windows-premium-guard-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Premium Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/18/windows-guard-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Guard Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/13/windows-be-on-guard-edition-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Abnormality Checker Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/11/windows-abnormality-checker-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/11/windows-abnormality-checker-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 11 May 2012 08:37:09 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Abnormality Checker]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3413</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Abnormality Checker. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsAbnormalityChecker. Windows Abnormality Checker is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Abnormality Checker</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsAbnormalityChecker" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAbnormalityChecker" target="_blank"><strong>Rogue.Win32.WindowsAbnormalityChecker</strong></a><strong>.</strong></p>
<p><strong><strong><strong><strong><strong><strong><strong>Windows Abnormality Checker</strong></strong></strong></strong> </strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Abnormality Checker.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Abnormality Checker.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsAbnormalityChecker_1.png"><img class="alignnone size-medium wp-image-3414" title="Rogue.Win32.WindowsAbnormalityChecker" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsAbnormalityChecker_1-400x234.png" alt="Rogue.Win32.WindowsAbnormalityChecker" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsAbnormalityChecker_2.png"><img class="alignnone size-medium wp-image-3415" title="Rogue.Win32.WindowsAbnormalityChecker" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsAbnormalityChecker_2-400x293.png" alt="Rogue.Win32.WindowsAbnormalityChecker" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsAbnormalityChecker_3.png"><img class="alignnone size-medium wp-image-3416" title="Rogue.Win32.WindowsAbnormalityChecker" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsAbnormalityChecker_3-400x293.png" alt="Rogue.Win32.WindowsAbnormalityChecker" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsAbnormalityChecker_4.png"><img class="alignnone size-medium wp-image-3417" title="Rogue.Win32.WindowsAbnormalityChecker" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsAbnormalityChecker_4-400x238.png" alt="Rogue.Win32.WindowsAbnormalityChecker" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsAbnormalityChecker_5.png"><img class="alignnone size-medium wp-image-3418" title="Rogue.Win32.WindowsAbnormalityChecker" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsAbnormalityChecker_5-400x253.png" alt="Rogue.Win32.WindowsAbnormalityChecker" width="400" height="253" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsAbnormalityChecker_6.png"><img class="alignnone size-medium wp-image-3419" title="Rogue.Win32.WindowsAbnormalityChecker" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsAbnormalityChecker_6-400x293.png" alt="Rogue.Win32.WindowsAbnormalityChecker" width="400" height="293" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Abnormality Checker </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAbnormalityChecker" target="_blank">Rogue.Win32.WindowsAbnormalityChecker</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Debugger Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/20/windows-foolproof-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Foolproof Protector Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/11/windows-abnormality-checker-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Pro Solutions Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/#comments</comments>
		<pubDate>Thu, 10 May 2012 10:53:00 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Pro Solutions]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3405</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Pro Solutions. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsProSolutions. Windows Pro Solutions is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<div>
<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Pro Solutions</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsProSolutions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProSolutions" target="_blank"><strong>Rogue.Win32.WindowsProSolutions</strong></a><strong>.</strong></p>
<p><strong><strong><strong><strong><strong><strong><strong>Windows Pro Solutions</strong></strong></strong></strong> </strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Pro Solutions.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Pro Solutions.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSolutions_1.png"><img class="alignnone size-medium wp-image-3406" title="Rogue.Win32.WindowsProSolutions" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSolutions_1-400x234.png" alt="Rogue.Win32.WindowsProSolutions" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSolutions_2.png"><img class="alignnone size-medium wp-image-3407" title="Rogue.Win32.WindowsProSolutions" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSolutions_2-400x293.png" alt="Rogue.Win32.WindowsProSolutions" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSolutions_3.png"><img class="alignnone size-medium wp-image-3408" title="Rogue.Win32.WindowsProSolutions" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSolutions_3-400x293.png" alt="Rogue.Win32.WindowsProSolutions" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSolutions_4.png"><img class="alignnone size-medium wp-image-3409" title="Rogue.Win32.WindowsProSolutions" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSolutions_4-400x238.png" alt="Rogue.Win32.WindowsProSolutions" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSolutions_5.png"><img class="alignnone size-medium wp-image-3410" title="Rogue.Win32.WindowsProSolutions" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSolutions_5-400x253.png" alt="Rogue.Win32.WindowsProSolutions" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Pro Solutions </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProSolutions" target="_blank">Rogue.Win32.WindowsProSolutions</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
</div>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/18/windows-guard-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Guard Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Debugger Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/20/windows-foolproof-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Foolproof Protector Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Sleek Performance Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/09/windows-sleek-performance-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/09/windows-sleek-performance-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 09 May 2012 11:26:37 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[WIndows Sleek Performance]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3398</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Sleek Performance. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsSleekPerformance. Windows Sleek Performance is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Sleek Performance</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsSleekPerformance" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSleekPerformance" target="_blank"><strong>Rogue.Win32.WindowsSleekPerformance</strong></a><strong>.</strong></p>
<p><strong><strong><strong><strong><strong><strong><strong>Windows Sleek Performance</strong></strong></strong></strong> </strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Sleek Performance.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Sleek Performance.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSleekPerformance_1.png"><img class="alignnone size-medium wp-image-3399" title="Rogue.Win32.WindowsSleekPerformance" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSleekPerformance_1-400x234.png" alt="Rogue.Win32.WindowsSleekPerformance" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSleekPerformance_2.png"><img class="alignnone size-medium wp-image-3400" title="Rogue.Win32.WindowsSleekPerformance" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSleekPerformance_2-400x293.png" alt="Rogue.Win32.WindowsSleekPerformance" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSleekPerformance_3.png"><img class="alignnone size-medium wp-image-3401" title="Rogue.Win32.WindowsSleekPerformance" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSleekPerformance_3-400x293.png" alt="Rogue.Win32.WindowsSleekPerformance" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSleekPerformance_4.png"><img class="alignnone size-medium wp-image-3402" title="Rogue.Win32.WindowsSleekPerformance" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSleekPerformance_4-400x238.png" alt="Rogue.Win32.WindowsSleekPerformance" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSleekPerformance_5.png"><img class="alignnone size-medium wp-image-3403" title="Rogue.Win32.WindowsSleekPerformance" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSleekPerformance_5-400x253.png" alt="Rogue.Win32.WindowsSleekPerformance" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Sleek Performance </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSleekPerformance" target="_blank">Rogue.Win32.WindowsSleekPerformance</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/25/windows-performance-adviser-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Performance Adviser Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Debugger Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/09/windows-sleek-performance-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows ProSecurity Scanner Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 08 May 2012 11:24:42 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows ProSecurity Scanner]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3391</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows ProSecurity Scanner. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsProSecurityScanner. Windows ProSecurity Scanner is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>
<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows ProSecurity Scanner</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsProSecurityScanner" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProSecurityScanner" target="_blank"><strong>Rogue.Win32.WindowsProSecurityScanner</strong></a><strong>.</strong></p>
<p><strong><strong><strong><strong><strong><strong><strong>Windows ProSecurity Scanner</strong></strong></strong></strong> </strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows ProSecurity Scanner.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows ProSecurity Scanner.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSecurityScanner_1.png"><img class="alignnone size-medium wp-image-3392" title="Rogue.Win32.WindowsProSecurityScanner" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSecurityScanner_1-400x234.png" alt="Rogue.Win32.WindowsProSecurityScanner" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSecurityScanner_2.png"><img class="alignnone size-medium wp-image-3393" title="Rogue.Win32.WindowsProSecurityScanner" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSecurityScanner_2-400x293.png" alt="Rogue.Win32.WindowsProSecurityScanner" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSecurityScanner_3.png"><img class="alignnone size-medium wp-image-3394" title="Rogue.Win32.WindowsProSecurityScanner" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSecurityScanner_3-400x293.png" alt="Rogue.Win32.WindowsProSecurityScanner" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSecurityScanner_4.png"><img class="alignnone size-medium wp-image-3395" title="Rogue.Win32.WindowsProSecurityScanner" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSecurityScanner_4-400x238.png" alt="Rogue.Win32.WindowsProSecurityScanner" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSecurityScanner_5.png"><img class="alignnone size-medium wp-image-3396" title="Rogue.Win32.WindowsProSecurityScanner" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProSecurityScanner_5-400x253.png" alt="Rogue.Win32.WindowsProSecurityScanner" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows ProSecurity Scanner </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProSecurityScanner" target="_blank">Rogue.Win32.WindowsProSecurityScanner</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
</div>
</div>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/18/windows-crucial-scanner-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Crucial Scanner Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Debugger Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Total Anti Malware Protection Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/07/total-anti-malware-protection-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/07/total-anti-malware-protection-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 07 May 2012 09:00:27 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Total Anti Malware Protection]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3383</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Total Anti Malware Protection. Emsisoft Anti-Malware detects this malware as Rogue.Win32.TotalAntiMalwareProtection. Total Anti Malware Protection is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong>Total Anti Malware Protection</strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.TotalAntiMalwareProtection" href="http://www.emsisoft.com/en/malware/?Adware.Win32.TotalAntiMalwareProtection" target="_blank"><strong>Rogue.Win32.TotalAntiMalwareProtection</strong></a><strong>.</strong></p>
<p><strong>Total Anti Malware Protection </strong><strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\2a967e\</li>
<li>%AllUsersProfile%\Application Data\2a967e\TAMPSys\</li>
<li>%AllUsersProfile%\Application Data\2a967e\BackUp\</li>
<li>%AllUsersProfile%\Application Data\2a967e\Quarantine Items\</li>
<li>%AllUsersProfile%\Application Data\2a967e\84.mof</li>
<li>%AllUsersProfile%\Application Data\2a967e\TAe0e_8011.exe</li>
<li>%AllUsersProfile%\Application Data\2a967e\TAMP.ico</li>
<li>%AllUsersProfile%\Application Data\TANAMNGQMP\</li>
<li>%AllUsersProfile%\Application Data\TANAMNGQMP\TASGMP.cfg</li>
<li>%AppData%\Total Anti Malware Protection\</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\Total Anti Malware Protection.lnk</li>
<li>%UserProfile%\Desktop\Total Anti Malware Protection.lnk</li>
<li>%UserProfile%\Recent\CLSV.drv</li>
<li>%UserProfile%\Recent\CLSV.exe</li>
<li>%UserProfile%\Recent\CLSV.tmp</li>
<li>%UserProfile%\Recent\energy.tmp</li>
<li>%UserProfile%\Recent\exec.tmp</li>
<li>%UserProfile%\Recent\fan.exe</li>
<li>%UserProfile%\Recent\hymt.sys</li>
<li>%UserProfile%\Recent\kernel32.exe</li>
<li>%UserProfile%\Recent\PE.dll</li>
<li>%UserProfile%\Recent\ppal.exe</li>
<li>%UserProfile%\Recent\sld.exe</li>
<li>%UserProfile%\Recent\ANTIGEN.sys</li>
<li>%UserProfile%\Start Menu\Total Anti Malware Protection.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Total Anti Malware Protection.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\Classes\TAe0e_8011.DocHostUIHandler<br />
Default = Implements DocHostUIHandler<br />
Clsid  = {3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\Classes\clsid\{3F2BBC05-40DF-11D2-9455-00104BC936FF}<br />
Default = Implements DocHostUIHandler<br />
LocalServer32  = %AllUsersProfile%\Application Data\2a967e\TAe0e_8011.exe<br />
ProgID  = TAe0e_8011.DocHostUIHandler</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run<br />
Total Anti Malware Protection = “%AllUsersProfile%\Application Data\2a967e\TAe0e_8011.exe” /s /d</li>
</ul>
<ul>
<li>HKEY_CLASSES_ROOT\Software\Microsoft\Internet Explorer\SearchScopes<br />
URL = http://findgala.com/?&amp;uid=8001&amp;q={searchTerms}</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation<br />
MSCompatibilityMode = 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download<br />
CheckExeSignatures = no<br />
RunInvalidSignatures = 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer<br />
IIL = 0×00000000<br />
ltHI = 0×00000000<br />
ltTST =0x00005f9f<br />
PRS = ”http://127.0.0.1:27777/?inj=%ORIGINAL%”<br />
RGF =0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes<br />
URL = http://findgala.com/?&amp;uid=8001&amp;q={searchTerms}</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings<br />
MigrateProxy = 0×00000001<br />
ProxyEnable = 0×00000000<br />
UID = “8001″</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap<br />
ProxyByPass = 0×00000001<br />
IntranetName = 0×00000001<br />
UNCAsIntranet = 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Total Anti Malware Protection<br />
DisplayName = “Total Anti Malware Protection”<br />
DisplayIcon = “%AllUsersProfile%\Application Data\2a967e\TAe0e_8011.exe,0″<br />
DisplayVersion = “1.1.0.1010″<br />
InstallLocation = “%AllUsersProfile%\Application Data\2a967e\”<br />
Publisher = “UIS Inc.”<br />
UninstallString = “%AllUsersProfile%\Application Data\2a967e\TAe0e_8011.exe” /del”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe<br />
Debugger = “svchost.exe”</li>
</ul>
<ul>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots</strong>:</p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.TotalAntiMalwareProtection_1.png"><img class="alignnone size-medium wp-image-3384" title="Rogue.Win32.TotalAntiMalwareProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.TotalAntiMalwareProtection_1-400x276.png" alt="Rogue.Win32.TotalAntiMalwareProtection" width="400" height="276" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.TotalAntiMalwareProtection_2.png"><img class="alignnone size-medium wp-image-3385" title="Rogue.Win32.TotalAntiMalwareProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.TotalAntiMalwareProtection_2-400x292.png" alt="Rogue.Win32.TotalAntiMalwareProtection" width="400" height="292" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.TotalAntiMalwareProtection_3.png"><img class="alignnone size-medium wp-image-3386" title="Rogue.Win32.TotalAntiMalwareProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.TotalAntiMalwareProtection_3-400x292.png" alt="Rogue.Win32.TotalAntiMalwareProtection" width="400" height="292" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><strong></strong><span style="color: #ff0000;"><strong>U2FD-S2LA-H4KA-UEPB</strong></span></pre>
<p><strong>How to remove the infection of Total Anti Malware Protection </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.TotalAntiMalwareProtection" target="_blank">Rogue.Win32.TotalAntiMalwareProtection</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/07/best-antivirus-software-rogue-removal-instructions/" rel="bookmark" class="crp_title">Best Antivirus Software Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/03/advanced-antispyware-solution-rogue-removal-instructions/" rel="bookmark" class="crp_title">Advanced Antispyware Solution Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Smart Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/02/21/home-malware-cleaner-rogue-removal-instructions/" rel="bookmark" class="crp_title">Home Malware Cleaner Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/07/total-anti-malware-protection-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Best Antivirus Software Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/07/best-antivirus-software-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/07/best-antivirus-software-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 07 May 2012 07:53:40 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Best Antivirus Software]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3376</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Best Antivirus Software. Emsisoft Anti-Malware detects this malware as Rogue.Win32.BestAntivirusSoftware. Best Antivirus Software is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong>Best Antivirus Software</strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.BestAntivirusSoftware" href="http://www.emsisoft.com/en/malware/?Adware.Win32.BestAntivirusSoftware" target="_blank"><strong>Rogue.Win32.BestAntivirusSoftware</strong></a><strong>.</strong></p>
<p><strong>Best Antivirus Software </strong><strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\2a967e\</li>
<li>%AllUsersProfile%\Application Data\2a967e\Quarantine Items\</li>
<li>%AllUsersProfile%\Application Data\2a967e\BackUp\</li>
<li>%AllUsersProfile%\Application Data\2a967e\BASSys\</li>
<li>%AllUsersProfile%\Application Data\2a967e\22.mof</li>
<li>%AllUsersProfile%\Application Data\2a967e\BA2a9_8001.exe</li>
<li>%AllUsersProfile%\Application Data\2a967e\BAS.ico</li>
<li>%AllUsersProfile%\Application Data\2a967e\bestantivirus.exe</li>
<li>%AllUsersProfile%\Application Data\BASVS\</li>
<li>%AllUsersProfile%\Application Data\BASVS\BAYZS.cfg</li>
<li>%AppData%\Best Antivirus Software\</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\Best Antivirus Software.lnk</li>
<li>%UserProfile%\Desktop\Best Antivirus Software.lnk</li>
<li>%UserProfile%\Recent\DBOLE.tmp</li>
<li>%UserProfile%\Recent\dudl.drv</li>
<li>%UserProfile%\Recent\eb.exe</li>
<li>%UserProfile%\Recent\energy.exe</li>
<li>%UserProfile%\Recent\energy.sys</li>
<li>%UserProfile%\Recent\exec.dll</li>
<li>%UserProfile%\Recent\fan.exe</li>
<li>%UserProfile%\Recent\fix.dll</li>
<li>%UserProfile%\Recent\gid.dll</li>
<li>%UserProfile%\Recent\PE.exe</li>
<li>%UserProfile%\Recent\snl2w.tmp</li>
<li>%UserProfile%\Recent\std.dll</li>
<li>%UserProfile%\Recent\tjd.tmp</li>
<li>%UserProfile%\Recent\cb.drv</li>
<li>%UserProfile%\Recent\CLSV.exe</li>
<li>%UserProfile%\Start Menu\Best Antivirus Software.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Best Antivirus Software.lnk</li>
<li>%Temp%\scandsk211d_8001.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\Classes\BA2a9_8001.DocHostUIHandler<br />
Default = Implements DocHostUIHandler<br />
Clsid  = {3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\Classes\clsid\{3F2BBC05-40DF-11D2-9455-00104BC936FF}<br />
Default = Implements DocHostUIHandler<br />
LocalServer32  = %AllUsersProfile%\Application Data\2a967e\BA2a9_8001.exe<br />
ProgID  = BA2a9_8001.DocHostUIHandler<br />
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run<br />
BAS = &#8220;%AllUsersProfile%\Application Data\2a967e\BA2a9_8001.exe&#8221; /s<br />
Best Antivirus Software = &#8220;%AllUsersProfile%\Application Data\2a967e\BA2a9_8001.exe&#8221; /s /d</li>
</ul>
<ul>
<li>HKEY_CLASSES_ROOT\Software\Microsoft\Internet Explorer\SearchScopes<br />
URL = http://findgala.com/?&amp;uid=8001&amp;q={searchTerms}</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation<br />
MSCompatibilityMode = 0&#215;00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download<br />
CheckExeSignatures = no<br />
RunInvalidSignatures = 0&#215;00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer<br />
IIL = 0&#215;00000000<br />
ltHI = 0&#215;00000000<br />
ltTST =0x00005f9f<br />
PRS =&#8221;http://127.0.0.1:27777/?inj=%ORIGINAL%&#8221;<br />
RGF =0&#215;00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes<br />
URL = http://findgala.com/?&amp;uid=8001&amp;q={searchTerms}</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings<br />
MigrateProxy = 0&#215;00000001<br />
ProxyEnable = 0&#215;00000000<br />
UID = &#8220;8001&#8243;</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap<br />
ProxyByPass = 0&#215;00000001<br />
IntranetName = 0&#215;00000001<br />
UNCAsIntranet = 0&#215;00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Best Antivirus Software<br />
DisplayName = &#8220;Best Antivirus Software&#8221;<br />
DisplayIcon = &#8220;%AllUsersProfile%\Application Data\2a967e\BA2a9_8001.exe,0&#8243;<br />
DisplayVersion = &#8220;1.1.0.1010&#8243;<br />
InstallLocation = &#8220;%AllUsersProfile%\Application Data\2a967e\&#8221;<br />
Publisher = &#8220;UIS Inc.&#8221;<br />
UninstallString = &#8220;%AllUsersProfile%\Application Data\2a967e\BA2a9_8001.exe&#8221; /del&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe<br />
Debugger = &#8220;svchost.exe&#8221;</li>
</ul>
<ul>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots</strong>:</p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.BestAntivirusSoftware_1.png"><img class="alignnone size-medium wp-image-3377" title="Rogue.Win32.BestAntivirusSoftware" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.BestAntivirusSoftware_1-400x292.png" alt="Rogue.Win32.BestAntivirusSoftware" width="400" height="292" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.BestAntivirusSoftware_2.png"><img class="alignnone size-medium wp-image-3378" title="Rogue.Win32.BestAntivirusSoftware" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.BestAntivirusSoftware_2-400x292.png" alt="Rogue.Win32.BestAntivirusSoftware" width="400" height="292" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.BestAntivirusSoftware_3.png"><img class="alignnone size-medium wp-image-3379" title="Rogue.Win32.BestAntivirusSoftware" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.BestAntivirusSoftware_3-400x303.png" alt="Rogue.Win32.BestAntivirusSoftware" width="400" height="303" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><strong></strong><span style="color: #ff0000;"><strong>U2FD-S2LA-H4KA-UEPB</strong></span></pre>
<p><strong>How to remove the infection of Best Antivirus Software </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BestAntivirusSoftware" target="_blank">Rogue.Win32.BestAntivirusSoftware</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/07/total-anti-malware-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Total Anti Malware Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/03/advanced-antispyware-solution-rogue-removal-instructions/" rel="bookmark" class="crp_title">Advanced Antispyware Solution Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Smart Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/02/21/home-malware-cleaner-rogue-removal-instructions/" rel="bookmark" class="crp_title">Home Malware Cleaner Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/12/26/home-security-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Home Security Solutions Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/07/best-antivirus-software-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Advanced User Patch Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/07/windows-advanced-user-patch-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/07/windows-advanced-user-patch-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 07 May 2012 03:54:04 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Advanced User Patch]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3368</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Advanced User Patch. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsAdvancedUserPatch. Windows Advanced User Patch is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>
<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Advanced User Patch</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsAdvancedUserPatch" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAdvancedUserPatch" target="_blank"><strong>Rogue.Win32.WindowsAdvancedUserPatch</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Advanced User Patch </strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Advanced User Patch.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Advanced User Patch.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsAdvancedUserPatch_1.png"><img class="alignnone size-medium wp-image-3369" title="Rogue.Win32.WindowsAdvancedUserPatch" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsAdvancedUserPatch_1-400x234.png" alt="Rogue.Win32.WindowsAdvancedUserPatch" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsAdvancedUserPatch_2.png"><img class="alignnone size-medium wp-image-3370" title="Rogue.Win32.WindowsAdvancedUserPatch" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsAdvancedUserPatch_2-400x293.png" alt="Rogue.Win32.WindowsAdvancedUserPatch" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsAdvancedUserPatch_3.png"><img class="alignnone size-medium wp-image-3371" title="Rogue.Win32.WindowsAdvancedUserPatch" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsAdvancedUserPatch_3-400x293.png" alt="Rogue.Win32.WindowsAdvancedUserPatch" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsAdvancedUserPatch_4.png"><img class="alignnone size-medium wp-image-3372" title="Rogue.Win32.WindowsAdvancedUserPatch" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsAdvancedUserPatch_4-400x238.png" alt="Rogue.Win32.WindowsAdvancedUserPatch" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsAdvancedUserPatch_5.png"><img class="alignnone size-medium wp-image-3373" title="Rogue.Win32.WindowsAdvancedUserPatch" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsAdvancedUserPatch_5-400x253.png" alt="Rogue.Win32.WindowsAdvancedUserPatch" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Advanced User Patch </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAdvancedUserPatch" target="_blank">Rogue.Win32.WindowsAdvancedUserPatch</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
</div>
</div>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-antivirus-patch-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Antivirus Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/13/windows-tools-patch-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Tools Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/07/windows-advanced-user-patch-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Pro Web Helper Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 07 May 2012 03:41:45 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Pro Web Helper]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3360</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Pro Web Helper. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsProWebHelper. Windows Pro Web Helper is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>
<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Pro Web Helper</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsProWebHelper" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProWebHelper" target="_blank"><strong>Rogue.Win32.WindowsProWebHelper</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Pro Web Helper </strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Pro Web Helper.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Pro Web Helper.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProWebHelper_1.png"><img class="alignnone size-medium wp-image-3361" title="Rogue.Win32.WindowsProWebHelper" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProWebHelper_1-400x234.png" alt="Rogue.Win32.WindowsProWebHelper" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProWebHelper_2.png"><img class="alignnone size-medium wp-image-3362" title="Rogue.Win32.WindowsProWebHelper" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProWebHelper_2-400x293.png" alt="Rogue.Win32.WindowsProWebHelper" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProWebHelper_3.png"><img class="alignnone size-medium wp-image-3363" title="Rogue.Win32.WindowsProWebHelper" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProWebHelper_3-400x293.png" alt="Rogue.Win32.WindowsProWebHelper" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProWebHelper_4.png"><img class="alignnone size-medium wp-image-3364" title="Rogue.Win32.WindowsProWebHelper" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProWebHelper_4-400x238.png" alt="Rogue.Win32.WindowsProWebHelper" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProWebHelper_5.png"><img class="alignnone size-medium wp-image-3365" title="Rogue.Win32.WindowsProWebHelper" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsProWebHelper_5-400x253.png" alt="Rogue.Win32.WindowsProWebHelper" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Pro Web Helper </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProWebHelper" target="_blank">Rogue.Win32.WindowsProWebHelper</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
</div>
</div>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-antihazard-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows AntiHazard Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Debugger Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/20/windows-foolproof-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Foolproof Protector Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Internet Booster Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/07/windows-internet-booster-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/07/windows-internet-booster-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 07 May 2012 03:28:39 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Internet Booster]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3352</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Internet Booster. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsInternetBooster. Windows Internet Booster is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<div>
<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Internet Booster</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsInternetBooster" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInternetBooster" target="_blank"><strong>Rogue.Win32.WindowsInternetBooster</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Internet Booster </strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Internet Booster.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Internet Booster.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsInternetBooster_1.png"><img class="alignnone size-medium wp-image-3353" title="Rogue.Win32.WindowsInternetBooster" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsInternetBooster_1-400x234.png" alt="Rogue.Win32.WindowsInternetBooster" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsInternetBooster_2.png"><img class="alignnone size-medium wp-image-3354" title="Rogue.Win32.WindowsInternetBooster" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsInternetBooster_2-400x293.png" alt="Rogue.Win32.WindowsInternetBooster" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsInternetBooster_3.png"><img class="alignnone size-medium wp-image-3355" title="Rogue.Win32.WindowsInternetBooster" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsInternetBooster_3-400x293.png" alt="Rogue.Win32.WindowsInternetBooster" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsInternetBooster_4.png"><img class="alignnone size-medium wp-image-3356" title="Rogue.Win32.WindowsInternetBooster" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsInternetBooster_4-400x238.png" alt="Rogue.Win32.WindowsInternetBooster" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsInternetBooster_5.png"><img class="alignnone size-medium wp-image-3357" title="Rogue.Win32.WindowsInternetBooster" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsInternetBooster_5-400x253.png" alt="Rogue.Win32.WindowsInternetBooster" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Internet Booster </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsInternetBooster" target="_blank">Rogue.Win32.WindowsInternetBooster</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
</div>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Debugger Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/20/windows-foolproof-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Foolproof Protector Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/07/windows-internet-booster-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Safety Module Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 01 May 2012 13:41:33 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Safety Module]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3344</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Safety Module. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsSafetyModule. Windows Safety Module is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Safety Module</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsSafetyModule" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyModule" target="_blank"><strong>Rogue.Win32.WindowsSafetyModule</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Safety Module </strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Safety Module.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Safety Module.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSafetyModule_1.png"><img class="alignnone size-medium wp-image-3345" title="Rogue.Win32.WindowsSafetyModule" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSafetyModule_1-400x234.png" alt="Rogue.Win32.WindowsSafetyModule" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSafetyModule_2.png"><img class="alignnone size-medium wp-image-3346" title="Rogue.Win32.WindowsSafetyModule" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSafetyModule_2-400x293.png" alt="Rogue.Win32.WindowsSafetyModule" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSafetyModule_3.png"><img class="alignnone size-medium wp-image-3347" title="Rogue.Win32.WindowsSafetyModule" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSafetyModule_3-400x293.png" alt="Rogue.Win32.WindowsSafetyModule" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSafetyModule_4.png"><img class="alignnone size-medium wp-image-3348" title="Rogue.Win32.WindowsSafetyModule" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSafetyModule_4-400x238.png" alt="Rogue.Win32.WindowsSafetyModule" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSafetyModule_5.png"><img class="alignnone size-medium wp-image-3349" title="Rogue.Win32.WindowsSafetyModule" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/05/Rogue.Win32.WindowsSafetyModule_5-400x253.png" alt="Rogue.Win32.WindowsSafetyModule" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Safety Module </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyModule" target="_blank">Rogue.Win32.WindowsSafetyModule</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Safety Toolkit Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Safety Checkpoint Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-safety-manager-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Safety Manager Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/18/windows-pro-safety-release-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Safety Release Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Recovery Series Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/30/windows-recovery-series-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/30/windows-recovery-series-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 30 Apr 2012 09:26:07 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Recovery Series]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3336</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Recovery Series. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsRecoverySeries. Windows Recovery Series is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<div>
<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Recovery Series</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsRecoverySeries" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRecoverySeries" target="_blank"><strong>Rogue.Win32.WindowsRecoverySeries</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Recovery Series </strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Recovery Series.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Recovery Series.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsRecoverySeries_1.png"><img class="alignnone size-medium wp-image-3337" title="Rogue.Win32.WindowsRecoverySeries" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsRecoverySeries_1-400x234.png" alt="Rogue.Win32.WindowsRecoverySeries" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsRecoverySeries_3.png"><img class="alignnone size-medium wp-image-3339" title="Rogue.Win32.WindowsRecoverySeries" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsRecoverySeries_3-400x293.png" alt="Rogue.Win32.WindowsRecoverySeries" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsRecoverySeries_4.png"><img class="alignnone size-medium wp-image-3340" title="Rogue.Win32.WindowsRecoverySeries" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsRecoverySeries_4-400x293.png" alt="Rogue.Win32.WindowsRecoverySeries" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsRecoverySeries_5.png"><img class="alignnone size-medium wp-image-3341" title="Rogue.Win32.WindowsRecoverySeries" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsRecoverySeries_5-400x238.png" alt="Rogue.Win32.WindowsRecoverySeries" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsRecoverySeries_6.png"><img class="alignnone size-medium wp-image-3342" title="Rogue.Win32.WindowsRecoverySeries" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsRecoverySeries_6-400x253.png" alt="Rogue.Win32.WindowsRecoverySeries" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Recovery Series </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRecoverySeries" target="_blank">Rogue.Win32.WindowsRecoverySeries</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
</div>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Debugger Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/20/windows-foolproof-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Foolproof Protector Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/30/windows-recovery-series-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data Recovery Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/30/data-recovery-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/30/data-recovery-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 30 Apr 2012 03:49:23 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Data Recovery]]></category>
		<category><![CDATA[DataRecovery.b]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[FakeSysDef]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3328</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Data Recovery. Emsisoft Anti-Malware detects this malware as Rogue.Win32.DataRecovery.b. Data Recovery is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Data Recovery</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.DataRecovery.b" href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataRecovery.b" target="_blank"><strong>Rogue.Win32.DataRecovery.b</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Data Recovery</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\peNIiagqcfvoe9</li>
<li>%AllUsersProfile%\Application Data\peNIiagqcfvoe9.exe</li>
<li>%AllUsersProfile%\Application Data\-peNIiagqcfvoe9</li>
<li>%AllUsersProfile%\Application Data\-peNIiagqcfvoe9r</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\Data_Recovery.lnk</li>
<li>%UserProfile%\Desktop\Data_Recovery.lnk</li>
<li>%UserProfile%\Desktop\Data_Recovery_License.txt</li>
<li>%UserProfile%\Local Settings\Temp\license.dat</li>
<li>%UserProfile%\Local Settings\Temp\RZQQnkXDzMfhGS.exe.tmp</li>
<li>%UserProfile%\Start Menu\Programs\Data Recovery\</li>
<li>%UserProfile%\Start Menu\Programs\Data Recovery\Data Recovery.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Data Recovery\Uninstall Data Recovery.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\<br />
nsreg = 00000000<br />
pth = 43003A005C0044006F00630075006D0065006E0074007300200061006E&#8230;</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures = no</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Main\<br />
Use FormSuggest = Yes</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
TaskbarGlomming = empty<br />
TaskbarGlomLevel = 0&#215;02000000<br />
Hidden = empty<br />
ShowSuperHidden = empty<br />
Start_ShowUser = 0&#215;01000000<br />
Start_ShowControlPanel = 0&#215;01000000<br />
Start_ShowHelp = 0&#215;01000000<br />
Start_ShowMyComputer = 0&#215;01000000<br />
Start_ShowMyDocs = 0&#215;01000000<br />
Start_ShowMyMusic = 0&#215;01000000<br />
Start_ShowMyGames = 0&#215;01000000<br />
Start_ShowMyPics = 0&#215;01000000<br />
Start_ShowPrinters = 0&#215;01000000<br />
Start_ShowRecentDocs = 0&#215;01000000<br />
Start_ShowRun = 0&#215;01000000<br />
Start_ShowSearch = 0&#215;01000000<br />
Start_ShowSetProgramAccessAndDefaults = 0&#215;01000000<br />
Start_ShowNetConn = 0&#215;01000000<br />
Start_ShowNetPlaces = 0&#215;01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Policies\Associations\<br />
LowRiskFileTypes = .zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;&#8230;</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Policies\Attachments\<br />
SaveZoneInformation = 0&#215;01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\<br />
peNIiagqcfvoe9 = %AllUsersProfile%\Application Data\peNIiagqcfvoe9.exe</li>
</ul>
<p><strong>Screenshosts:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.DataRecovery.b_1.png"><img class="alignnone size-medium wp-image-3329" title="Rogue.Win32.DataRecovery.b" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.DataRecovery.b_1-400x331.png" alt="Rogue.Win32.DataRecovery.b" width="400" height="331" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.DataRecovery.b_2.png"><img class="alignnone size-medium wp-image-3330" title="Rogue.Win32.DataRecovery.b" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.DataRecovery.b_2-400x331.png" alt="Rogue.Win32.DataRecovery.b" width="400" height="331" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.DataRecovery.b_3.png"><img class="alignnone size-medium wp-image-3331" title="Rogue.Win32.DataRecovery.b" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.DataRecovery.b_3-400x240.png" alt="Rogue.Win32.DataRecovery.b" width="400" height="240" /></a></p>
<p>To register this rogue application you can try the following serial number and enter any email:</p>
<pre><span style="color: #ff0000;"><strong>08869246386344953972969146034087</strong></span>
<strong></strong></pre>
<p><strong>How to remove the infection of Data Recovery</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataRecovery.b" target="_blank">Rogue.Win32.DataRecovery.b</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/09/15/data-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/02/system-check-rogue-removal-instructions/" rel="bookmark" class="crp_title">System Check Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/03/data-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/15/system-fix-rogue-removal-instructions/" rel="bookmark" class="crp_title">System Fix Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/system-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">System Restore Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/30/data-recovery-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Safety Checkpoint Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 27 Apr 2012 13:01:08 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Safety Checkpoint]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3321</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Safety Checkpoint. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsSafetyCheckpoint. Windows Safety Checkpoint is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Safety Checkpoint</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsSafetyCheckpoint" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyCheckpoint" target="_blank"><strong>Rogue.Win32.WindowsSafetyCheckpoint</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Safety Checkpoint </strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Safety Checkpoint.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Safety Checkpoint.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyCheckpoint_1.png"><img class="alignnone size-medium wp-image-3322" title="Rogue.Win32.WindowsSafetyCheckpoint" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyCheckpoint_1-400x234.png" alt="Rogue.Win32.WindowsSafetyCheckpoint" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyCheckpoint_2.png"><img class="alignnone size-medium wp-image-3323" title="Rogue.Win32.WindowsSafetyCheckpoint" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyCheckpoint_2-400x293.png" alt="Rogue.Win32.WindowsSafetyCheckpoint" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyCheckpoint_3.png"><img class="alignnone size-medium wp-image-3324" title="Rogue.Win32.WindowsSafetyCheckpoint" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyCheckpoint_3-400x293.png" alt="Rogue.Win32.WindowsSafetyCheckpoint" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyCheckpoint_4.png"><img class="alignnone size-medium wp-image-3325" title="Rogue.Win32.WindowsSafetyCheckpoint" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyCheckpoint_4-400x238.png" alt="Rogue.Win32.WindowsSafetyCheckpoint" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyCheckpoint_5.png"><img class="alignnone size-medium wp-image-3326" title="Rogue.Win32.WindowsSafetyCheckpoint" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyCheckpoint_5-400x253.png" alt="Rogue.Win32.WindowsSafetyCheckpoint" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Safety Checkpoint </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyCheckpoint" target="_blank">Rogue.Win32.WindowsSafetyCheckpoint</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Safety Toolkit Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-safety-manager-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Safety Manager Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/18/windows-pro-safety-release-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Safety Release Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Premium Guard Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/26/windows-premium-guard-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/26/windows-premium-guard-rogue-removal-instructions/#comments</comments>
		<pubDate>Thu, 26 Apr 2012 06:44:16 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Premium Guard]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3313</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Premium Guard. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsPremiumGuard. Windows Premium Guard is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong><strong>Windows Premium Guard</strong></strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsPremiumGuard" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPremiumGuard" target="_blank"><strong>Rogue.Win32.WindowsPremiumGuard</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Premium Guard </strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Premium Guard.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Premium Guard.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsPremiumGuard_1.png"><img class="alignnone size-medium wp-image-3314" title="Rogue.Win32.WindowsPremiumGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsPremiumGuard_1-400x234.png" alt="Rogue.Win32.WindowsPremiumGuard" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsPremiumGuard_2.png"><img class="alignnone size-medium wp-image-3315" title="Rogue.Win32.WindowsPremiumGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsPremiumGuard_2-400x293.png" alt="Rogue.Win32.WindowsPremiumGuard" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsPremiumGuard_3.png"><img class="alignnone size-medium wp-image-3316" title="Rogue.Win32.WindowsPremiumGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsPremiumGuard_3-400x293.png" alt="Rogue.Win32.WindowsPremiumGuard" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsPremiumGuard_4.png"><img class="alignnone size-medium wp-image-3317" title="Rogue.Win32.WindowsPremiumGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsPremiumGuard_4-400x238.png" alt="Rogue.Win32.WindowsPremiumGuard" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsPremiumGuard_5.png"><img class="alignnone size-medium wp-image-3318" title="Rogue.Win32.WindowsPremiumGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsPremiumGuard_5-400x253.png" alt="Rogue.Win32.WindowsPremiumGuard" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Premium Guard </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPremiumGuard" target="_blank">Rogue.Win32.WindowsPremiumGuard</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/18/windows-guard-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Guard Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/13/windows-be-on-guard-edition-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Be-on Guard Edition Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/26/windows-premium-guard-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Efficiency Accelerator Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/25/windows-efficiency-accelerator-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/25/windows-efficiency-accelerator-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 25 Apr 2012 14:03:46 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Efficiency Accelerator]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3305</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Efficiency Accelerator. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsEfficiencyAccelerator. Windows Efficiency Accelerator is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Efficiency Accelerator</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsEfficiencyAccelerator" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEfficiencyAccelerator" target="_blank"><strong>Rogue.Win32.WindowsEfficiencyAccelerator</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Efficiency Accelerator </strong></strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Efficiency Accelerator.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Efficiency Accelerator.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsEfficiencyAccelerator_1.png"><img class="alignnone size-medium wp-image-3306" title="Rogue.Win32.WindowsEfficiencyAccelerator" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsEfficiencyAccelerator_1-400x234.png" alt="Rogue.Win32.WindowsEfficiencyAccelerator" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsEfficiencyAccelerator_2.png"><img class="alignnone size-medium wp-image-3307" title="Rogue.Win32.WindowsEfficiencyAccelerator" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsEfficiencyAccelerator_2-400x293.png" alt="Rogue.Win32.WindowsEfficiencyAccelerator" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsEfficiencyAccelerator_3.png"><img class="alignnone size-medium wp-image-3308" title="Rogue.Win32.WindowsEfficiencyAccelerator" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsEfficiencyAccelerator_3-400x293.png" alt="Rogue.Win32.WindowsEfficiencyAccelerator" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsEfficiencyAccelerator_4.png"><img class="alignnone size-medium wp-image-3309" title="Rogue.Win32.WindowsEfficiencyAccelerator" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsEfficiencyAccelerator_4-400x238.png" alt="Rogue.Win32.WindowsEfficiencyAccelerator" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsEfficiencyAccelerator_5.png"><img class="alignnone size-medium wp-image-3310" title="Rogue.Win32.WindowsEfficiencyAccelerator" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsEfficiencyAccelerator_5-400x253.png" alt="Rogue.Win32.WindowsEfficiencyAccelerator" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Efficiency Accelerator </strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEfficiencyAccelerator" target="_blank">Rogue.Win32.WindowsEfficiencyAccelerator</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/09/windows-efficiency-reservoir-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Efficiency Reservoir Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Debugger Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/25/windows-efficiency-accelerator-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Performance Adviser Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/25/windows-performance-adviser-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/25/windows-performance-adviser-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 25 Apr 2012 05:14:48 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Performance Adviser]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3297</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Performance Adviser. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsPerformanceAdviser. Windows Performance Adviser is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Performance Adviser</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsPerformanceAdviser" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceAdviser" target="_blank"><strong>Rogue.Win32.WindowsPerformanceAdviser</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Performance Adviser</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Performance Adviser.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Performance Adviser.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsPerformanceAdviser_1.png"><img class="alignnone size-medium wp-image-3298" title="Rogue.Win32.WindowsPerformanceAdviser" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsPerformanceAdviser_1-400x234.png" alt="Rogue.Win32.WindowsPerformanceAdviser" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsPerformanceAdviser_2.png"><img class="alignnone size-medium wp-image-3299" title="Rogue.Win32.WindowsPerformanceAdviser" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsPerformanceAdviser_2-400x293.png" alt="Rogue.Win32.WindowsPerformanceAdviser" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsPerformanceAdviser_3.png"><img class="alignnone size-medium wp-image-3300" title="Rogue.Win32.WindowsPerformanceAdviser" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsPerformanceAdviser_3-400x293.png" alt="Rogue.Win32.WindowsPerformanceAdviser" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsPerformanceAdviser_4.png"><img class="alignnone size-medium wp-image-3301" title="Rogue.Win32.WindowsPerformanceAdviser" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsPerformanceAdviser_4-400x238.png" alt="Rogue.Win32.WindowsPerformanceAdviser" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsPerformanceAdviser_5.png"><img class="alignnone size-medium wp-image-3302" title="Rogue.Win32.WindowsPerformanceAdviser" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsPerformanceAdviser_5-400x253.png" alt="Rogue.Win32.WindowsPerformanceAdviser" width="400" height="253" /></a></p>
<p>&nbsp;</p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Performance Adviser</strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPerformanceAdviser" target="_blank">Rogue.Win32.WindowsPerformanceAdviser</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/09/windows-sleek-performance-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Sleek Performance Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Debugger Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/25/windows-performance-adviser-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Safety Toolkit Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 23 Apr 2012 02:59:26 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Safety Toolkit]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3285</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Safety Toolkit. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsSafetyToolkit. Windows Safety Toolkit is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<div>
<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Safety Toolkit</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsSafetyToolkit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyToolkit" target="_blank"><strong>Rogue.Win32.WindowsSafetyToolkit</strong></a><strong>.</strong></p>
<p><strong><strong><strong></strong></strong></strong><strong><strong><strong>Windows Safety Toolkit</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Safety Toolkit.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Safety Toolkit.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<div><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyToolkit_1.png"><img class="alignnone size-medium wp-image-3286" title="Rogue.Win32.WindowsSafetyToolkit" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyToolkit_1-400x234.png" alt="Rogue.Win32.WindowsSafetyToolkit" width="400" height="234" /></a></div>
<div></div>
<div><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyToolkit_2.png"><img class="alignnone size-medium wp-image-3287" title="Rogue.Win32.WindowsSafetyToolkit" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyToolkit_2-400x293.png" alt="Rogue.Win32.WindowsSafetyToolkit" width="400" height="293" /></a></div>
<div></div>
<div><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyToolkit_3.png"><img class="alignnone size-medium wp-image-3288" title="Rogue.Win32.WindowsSafetyToolkit" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyToolkit_3-400x293.png" alt="Rogue.Win32.WindowsSafetyToolkit" width="400" height="293" /></a></div>
<div></div>
<div><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyToolkit_4.png"><img class="alignnone size-medium wp-image-3289" title="Rogue.Win32.WindowsSafetyToolkit" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyToolkit_4-400x238.png" alt="Rogue.Win32.WindowsSafetyToolkit" width="400" height="238" /></a></div>
<div></div>
<div><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyToolkit_5.png"><img class="alignnone size-medium wp-image-3290" title="Rogue.Win32.WindowsSafetyToolkit" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyToolkit_5-400x253.png" alt="Rogue.Win32.WindowsSafetyToolkit" width="400" height="253" /></a></div>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Safety Toolkit</strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyToolkit" target="_blank">Rogue.Win32.WindowsSafetyToolkit</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
</div>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Safety Checkpoint Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-safety-manager-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Safety Manager Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/18/windows-pro-safety-release-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Safety Release Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Foolproof Protector Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/20/windows-foolproof-protector-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/20/windows-foolproof-protector-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 20 Apr 2012 08:49:53 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Foolproof Protector]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3278</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Foolproof Protector. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsFoolproofProtector. Windows Foolproof Protector is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]]]></description>
			<content:encoded><![CDATA[<div>
<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Foolproof Protector</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsFoolproofProtector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFoolproofProtector" target="_blank"><strong>Rogue.Win32.WindowsFoolproofProtector</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Foolproof Protector</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Foolproof Protector.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Foolproof Protector.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsFoolproofProtector_1.png"><img class="alignnone size-medium wp-image-3279" title="Rogue.Win32.WindowsFoolproofProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsFoolproofProtector_1-400x234.png" alt="Rogue.Win32.WindowsFoolproofProtector" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsFoolproofProtector_2.png"><img class="alignnone size-medium wp-image-3280" title="Rogue.Win32.WindowsFoolproofProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsFoolproofProtector_2-400x293.png" alt="Rogue.Win32.WindowsFoolproofProtector" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsFoolproofProtector_3.png"><img class="alignnone size-medium wp-image-3281" title="Rogue.Win32.WindowsFoolproofProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsFoolproofProtector_3-400x293.png" alt="Rogue.Win32.WindowsFoolproofProtector" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsFoolproofProtector_4.png"><img class="alignnone size-medium wp-image-3282" title="Rogue.Win32.WindowsFoolproofProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsFoolproofProtector_4-400x238.png" alt="Rogue.Win32.WindowsFoolproofProtector" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsFoolproofProtector_5.png"><img class="alignnone size-medium wp-image-3283" title="Rogue.Win32.WindowsFoolproofProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsFoolproofProtector_5-400x253.png" alt="Rogue.Win32.WindowsFoolproofProtector" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong><strong><strong><strong>Windows Foolproof Protector</strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFoolproofProtector" target="_blank">Rogue.Win32.WindowsFoolproofProtector</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
</div>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/10/windows-component-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Component Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Debugger Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/20/windows-foolproof-protector-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Guard Solutions Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/18/windows-guard-solutions-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/18/windows-guard-solutions-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 18 Apr 2012 11:12:11 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Guard Solutions]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3271</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Guard Solutions. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsGuardSolutions. Windows Guard Solutions is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Guard Solutions</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsGuardSolutions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsGuardSolutions" target="_blank"><strong>Rogue.Win32.WindowsGuardSolutions</strong></a><strong>.</strong></p>
<p><strong></strong><strong><strong><strong>Windows Guard Solutions</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Guard Solutions.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Guard Solutions.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsGuardSolutions_1.png"><img class="alignnone size-medium wp-image-3272" title="Rogue.Win32.WindowsGuardSolutions" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsGuardSolutions_1-400x234.png" alt="Rogue.Win32.WindowsGuardSolutions" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsGuardSolutions_2.png"><img class="alignnone size-medium wp-image-3273" title="Rogue.Win32.WindowsGuardSolutions" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsGuardSolutions_2-400x293.png" alt="Rogue.Win32.WindowsGuardSolutions" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsGuardSolutions_3.png"><img class="alignnone size-medium wp-image-3274" title="Rogue.Win32.WindowsGuardSolutions" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsGuardSolutions_3-400x293.png" alt="Rogue.Win32.WindowsGuardSolutions" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsGuardSolutions_4.png"><img class="alignnone size-medium wp-image-3275" title="Rogue.Win32.WindowsGuardSolutions" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsGuardSolutions_4-400x238.png" alt="Rogue.Win32.WindowsGuardSolutions" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsGuardSolutions_5.png"><img class="alignnone size-medium wp-image-3276" title="Rogue.Win32.WindowsGuardSolutions" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsGuardSolutions_5-400x253.png" alt="Rogue.Win32.WindowsGuardSolutions" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<div>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong><strong><strong><strong>Windows Guard Solutions</strong></strong></strong></strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsGuardSolutions" target="_blank">Rogue.Win32.WindowsGuardSolutions</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/26/windows-premium-guard-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Premium Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/13/windows-be-on-guard-edition-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Be-on Guard Edition Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/18/windows-guard-solutions-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Crucial Scanner Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/18/windows-crucial-scanner-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/18/windows-crucial-scanner-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 18 Apr 2012 02:22:15 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Crucial Scanner]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3264</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Crucial Scanner. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsCrucialScanner. Windows Crucial Scanner is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>
<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Crucial Scanner</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsCrucialScanner" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrucialScanner" target="_blank"><strong>Rogue.Win32.WindowsCrucialScanner</strong></a><strong>.</strong></p>
<p><strong>Windows Crucial Scanner</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Crucial Scanner.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Crucial Scanner.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCrucialScanner_1.png"><img class="alignnone size-medium wp-image-3265" title="Rogue.Win32.WindowsCrucialScanner" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCrucialScanner_1-400x234.png" alt="Rogue.Win32.WindowsCrucialScanner" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCrucialScanner_2.png"><img class="alignnone size-medium wp-image-3266" title="Rogue.Win32.WindowsCrucialScanner" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCrucialScanner_2-400x293.png" alt="Rogue.Win32.WindowsCrucialScanner" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCrucialScanner_3.png"><img class="alignnone size-medium wp-image-3267" title="Rogue.Win32.WindowsCrucialScanner" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCrucialScanner_3-400x293.png" alt="Rogue.Win32.WindowsCrucialScanner" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCrucialScanner_4.png"><img class="alignnone size-medium wp-image-3268" title="Rogue.Win32.WindowsCrucialScanner" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCrucialScanner_4-400x238.png" alt="Rogue.Win32.WindowsCrucialScanner" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCrucialScanner_5.png"><img class="alignnone size-medium wp-image-3269" title="Rogue.Win32.WindowsCrucialScanner" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCrucialScanner_5-400x253.png" alt="Rogue.Win32.WindowsCrucialScanner" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
</div>
<div>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of <strong><strong><strong>Windows Crucial Scanner</strong></strong></strong> </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCrucialScanner" target="_blank">Rogue.Win32.WindowsCrucialScanner</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
</div>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/08/windows-prosecurity-scanner-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows ProSecurity Scanner Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Debugger Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/18/windows-crucial-scanner-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Safety Manager Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/17/windows-safety-manager-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/17/windows-safety-manager-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 17 Apr 2012 10:35:37 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Safety Manager]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3255</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Safety Manager. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsSafetyManager. Windows Safety Manager is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<div>
<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Safety Manager</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsSafetyManager" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyManager" target="_blank"><strong>Rogue.Win32.WindowsSafetyManager</strong></a><strong>.</strong></p>
<p><strong><strong><strong></strong></strong><strong><strong><strong>Windows Safety Manager</strong></strong></strong> </strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Safety Manager.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Safety Manager.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyManager_1.png"><img class="alignnone size-medium wp-image-3256" title="Rogue.Win32.WindowsSafetyManager" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyManager_1-400x234.png" alt="Rogue.Win32.WindowsSafetyManager" width="400" height="234" /></a></p>
</div>
<div></div>
<div><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyManager_2.png"><img class="alignnone size-medium wp-image-3257" title="Rogue.Win32.WindowsSafetyManager" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyManager_2-400x293.png" alt="Rogue.Win32.WindowsSafetyManager" width="400" height="293" /></a></div>
<div></div>
<div><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyManager_3.png"><img class="alignnone size-medium wp-image-3258" title="Rogue.Win32.WindowsSafetyManager" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyManager_3-400x293.png" alt="Rogue.Win32.WindowsSafetyManager" width="400" height="293" /></a></div>
<div></div>
<div><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyManager_4.png"><img class="alignnone size-medium wp-image-3259" title="Rogue.Win32.WindowsSafetyManager" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyManager_4-400x238.png" alt="Rogue.Win32.WindowsSafetyManager" width="400" height="238" /></a></div>
<div></div>
<div>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyManager_5.png"><img class="alignnone size-medium wp-image-3260" title="Rogue.Win32.WindowsSafetyManager" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsSafetyManager_5-400x253.png" alt="Rogue.Win32.WindowsSafetyManager" width="400" height="253" /></a><br title="Rogue.Win32.WindowsAntivirusPatch" />To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Safety Manager </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSafetyManager" target="_blank">Rogue.Win32.WindowsSafetyManager</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/23/windows-safety-toolkit-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Safety Toolkit Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/27/windows-safety-checkpoint-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Safety Checkpoint Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/01/windows-safety-module-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Safety Module Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/18/windows-pro-safety-release-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Safety Release Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/17/windows-safety-manager-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Antivirus Patch Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/17/windows-antivirus-patch-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/17/windows-antivirus-patch-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 17 Apr 2012 05:23:28 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Antivirus Patch]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3248</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Antivirus Patch. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsAntivirusPatch. Windows Antivirus Patch is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Antivirus Patch</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsAntivirusPatch" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntivirusPatch" target="_blank"><strong>Rogue.Win32.WindowsAntivirusPatch</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Antivirus Patch</strong></strong> </strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Antivirus Patch.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Antivirus Patch.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsAntivirusPatch_1.png"><img class="alignnone size-medium wp-image-3249" title="Rogue.Win32.WindowsAntivirusPatch" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsAntivirusPatch_1-400x234.png" alt="Rogue.Win32.WindowsAntivirusPatch" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsAntivirusPatch_2.png"><img class="alignnone size-medium wp-image-3250" title="Rogue.Win32.WindowsAntivirusPatch" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsAntivirusPatch_2-400x293.png" alt="Rogue.Win32.WindowsAntivirusPatch" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsAntivirusPatch_3.png"><img class="alignnone size-medium wp-image-3251" title="Rogue.Win32.WindowsAntivirusPatch" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsAntivirusPatch_3-400x293.png" alt="Rogue.Win32.WindowsAntivirusPatch" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsAntivirusPatch_4.png"><img class="alignnone size-medium wp-image-3252" title="Rogue.Win32.WindowsAntivirusPatch" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsAntivirusPatch_4-400x238.png" alt="Rogue.Win32.WindowsAntivirusPatch" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsAntivirusPatch_5.png"><img class="alignnone size-medium wp-image-3253" title="Rogue.Win32.WindowsAntivirusPatch" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsAntivirusPatch_5-400x253.png" alt="Rogue.Win32.WindowsAntivirusPatch" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Antivirus Patch </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntivirusPatch" target="_blank">Rogue.Win32.WindowsAntivirusPatch</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-safety-manager-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Safety Manager Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-advanced-user-patch-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Advanced User Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/13/windows-tools-patch-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Tools Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/17/windows-antivirus-patch-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Protection Unit Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/17/windows-protection-unit-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/17/windows-protection-unit-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 17 Apr 2012 05:14:21 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Protection Unit]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3241</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Protection Unit. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsProtectionUnit. Windows Protection Unit is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Protection Unit</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsProtectionUnit" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionUnit" target="_blank"><strong>Rogue.Win32.WindowsProtectionUnit</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Protection Unit</strong></strong> </strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Protection Unit.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Protection Unit.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsProtectionUnit_1.png"><img class="alignnone size-medium wp-image-3242" title="Rogue.Win32.WindowsProtectionUnit" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsProtectionUnit_1-400x234.png" alt="Rogue.Win32.WindowsProtectionUnit" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsProtectionUnit_2.png"><img class="alignnone size-medium wp-image-3243" title="Rogue.Win32.WindowsProtectionUnit" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsProtectionUnit_2-400x293.png" alt="Rogue.Win32.WindowsProtectionUnit" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsProtectionUnit_3.png"><img class="alignnone size-medium wp-image-3244" title="Rogue.Win32.WindowsProtectionUnit" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsProtectionUnit_3-400x293.png" alt="Rogue.Win32.WindowsProtectionUnit" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsProtectionUnit_4.png"><img class="alignnone size-medium wp-image-3245" title="Rogue.Win32.WindowsProtectionUnit" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsProtectionUnit_4-400x238.png" alt="Rogue.Win32.WindowsProtectionUnit" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsProtectionUnit_5.png"><img class="alignnone size-medium wp-image-3246" title="Rogue.Win32.WindowsProtectionUnit" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsProtectionUnit_5-400x253.png" alt="Rogue.Win32.WindowsProtectionUnit" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Protection Unit </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionUnit" target="_blank">Rogue.Win32.WindowsProtectionUnit</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Debugger Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/04/windows-custodian-utility-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Custodian Utility Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/17/windows-protection-unit-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Antibreaking System Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/11/windows-antibreaking-system-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/11/windows-antibreaking-system-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 11 Apr 2012 08:33:32 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Antibreaking System]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3231</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Antibreaking System. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsAntibreakingSystem. Windows Antibreaking System is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Antibreaking System</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsAntibreakingSystem" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntibreakingSystem" target="_blank"><strong>Rogue.Win32.WindowsAntibreakingSystem</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows </strong></strong>Antibreaking System </strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Antibreaking System.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Antibreaking System.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsAntibreakingSystem_1.png"><img class="alignnone size-medium wp-image-3232" title="Rogue.Win32.WindowsAntibreakingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsAntibreakingSystem_1-400x234.png" alt="Rogue.Win32.WindowsAntibreakingSystem" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsAntibreakingSystem_2.png"><img class="alignnone size-medium wp-image-3233" title="Rogue.Win32.WindowsAntibreakingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsAntibreakingSystem_2-400x293.png" alt="Rogue.Win32.WindowsAntibreakingSystem" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsAntibreakingSystem_3.png"><img class="alignnone size-medium wp-image-3234" title="Rogue.Win32.WindowsAntibreakingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsAntibreakingSystem_3-400x293.png" alt="Rogue.Win32.WindowsAntibreakingSystem" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsAntibreakingSystem_4.png"><img class="alignnone size-medium wp-image-3235" title="Rogue.Win32.WindowsAntibreakingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsAntibreakingSystem_4-400x238.png" alt="Rogue.Win32.WindowsAntibreakingSystem" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsAntibreakingSystem_5.png"><img class="alignnone size-medium wp-image-3236" title="Rogue.Win32.WindowsAntibreakingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsAntibreakingSystem_5-400x253.png" alt="Rogue.Win32.WindowsAntibreakingSystem" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Antibreaking System </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntibreakingSystem" target="_blank">Rogue.Win32.WindowsAntibreakingSystem</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-warding-system-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Warding System Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Debugger Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/11/windows-antibreaking-system-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Component Protector Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/10/windows-component-protector-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/10/windows-component-protector-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 10 Apr 2012 10:13:23 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Component Protector]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3223</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Component Protector. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsComponentProtector. Windows Component Protector is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Component Protector</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsComponentProtector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsComponentProtector" target="_blank"><strong>Rogue.Win32.WindowsComponentProtector</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Component Protector</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Component Protector.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Component Protector.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsComponentProtector_1.png"><img class="alignnone size-medium wp-image-3224" title="Rogue.Win32.WindowsComponentProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsComponentProtector_1-400x234.png" alt="Rogue.Win32.WindowsComponentProtector" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsComponentProtector_2.png"><img class="alignnone size-medium wp-image-3225" title="Rogue.Win32.WindowsComponentProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsComponentProtector_2-400x293.png" alt="Rogue.Win32.WindowsComponentProtector" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsComponentProtector_3.png"><img class="alignnone size-medium wp-image-3226" title="Rogue.Win32.WindowsComponentProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsComponentProtector_3-400x293.png" alt="Rogue.Win32.WindowsComponentProtector" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsComponentProtector_4.png"><img class="alignnone size-medium wp-image-3227" title="Rogue.Win32.WindowsComponentProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsComponentProtector_4-400x238.png" alt="Rogue.Win32.WindowsComponentProtector" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsComponentProtector_5.png"><img class="alignnone size-medium wp-image-3228" title="Rogue.Win32.WindowsComponentProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsComponentProtector_5-400x253.png" alt="Rogue.Win32.WindowsComponentProtector" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Component Protector </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsComponentProtector" target="_blank">Rogue.Win32.WindowsComponentProtector</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/20/windows-foolproof-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Foolproof Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Debugger Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/10/windows-component-protector-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Stability Maximizer Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/09/windows-stability-maximizer-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/09/windows-stability-maximizer-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 09 Apr 2012 14:42:22 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Stability Maximizer]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3215</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Stability Maximizer. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsStabilityMaximizer. Windows Stability Maximizer is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Stability Maximizer</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsStabilityMaximizer" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityMaximizer" target="_blank"><strong>Rogue.Win32.WindowsStabilityMaximizer</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Stability Maximizer</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Stability Maximizer.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Stability Maximizer.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsStabilityMaximizer_1.png"><img class="alignnone size-medium wp-image-3216" title="Rogue.Win32.WindowsStabilityMaximizer" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsStabilityMaximizer_1-400x234.png" alt="Rogue.Win32.WindowsStabilityMaximizer" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsStabilityMaximizer_2.png"><img class="alignnone size-medium wp-image-3217" title="Rogue.Win32.WindowsStabilityMaximizer" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsStabilityMaximizer_2-400x293.png" alt="Rogue.Win32.WindowsStabilityMaximizer" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsStabilityMaximizer_3.png"><img class="alignnone size-medium wp-image-3218" title="Rogue.Win32.WindowsStabilityMaximizer" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsStabilityMaximizer_3-400x293.png" alt="Rogue.Win32.WindowsStabilityMaximizer" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsStabilityMaximizer_4.png"><img class="alignnone size-medium wp-image-3219" title="Rogue.Win32.WindowsStabilityMaximizer" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsStabilityMaximizer_4-400x238.png" alt="Rogue.Win32.WindowsStabilityMaximizer" width="400" height="238" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Stability Maximizer </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityMaximizer" target="_blank">Rogue.Win32.WindowsStabilityMaximizer</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Debugger Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/04/windows-custodian-utility-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Custodian Utility Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/09/windows-stability-maximizer-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Cleaning Tools Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/09/windows-cleaning-tools-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/09/windows-cleaning-tools-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 09 Apr 2012 13:45:30 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Cleaning Tools]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3209</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Cleaning Tools. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsCleaningTools. Windows Cleaning Tools is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Cleaning Tools</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsCleaningTools" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCleaningTools" target="_blank"><strong>Rogue.Win32.WindowsCleaningTools</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Cleaning Tools</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Cleaning Tools.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Cleaning Tools.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCleaningTools_1.png"><img class="alignnone size-medium wp-image-3210" title="Rogue.Win32.WindowsCleaningTools" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCleaningTools_1-400x234.png" alt="Rogue.Win32.WindowsCleaningTools" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCleaningTools_2.png"><img class="alignnone size-medium wp-image-3211" title="Rogue.Win32.WindowsCleaningTools" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCleaningTools_2-400x293.png" alt="Rogue.Win32.WindowsCleaningTools" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCleaningTools_3.png"><img class="alignnone size-medium wp-image-3212" title="Rogue.Win32.WindowsCleaningTools" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCleaningTools_3-400x293.png" alt="Rogue.Win32.WindowsCleaningTools" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCleaningTools_4.png"><img class="alignnone size-medium wp-image-3213" title="Rogue.Win32.WindowsCleaningTools" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCleaningTools_4-400x238.png" alt="Rogue.Win32.WindowsCleaningTools" width="400" height="238" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Cleaning Tools </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCleaningTools" target="_blank">Rogue.Win32.WindowsCleaningTools</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/13/windows-tools-patch-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Tools Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Debugger Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/09/windows-cleaning-tools-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Efficiency Reservoir Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/09/windows-efficiency-reservoir-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/09/windows-efficiency-reservoir-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 09 Apr 2012 04:01:44 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malwar Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Efficiency Reservoir]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3202</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Efficiency Reservoir. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsEfficiencyReservoir. Windows Efficiency Reservoir is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Efficiency Reservoir</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsEfficiencyReservoir" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEfficiencyReservoir" target="_blank"><strong>Rogue.Win32.WindowsEfficiencyReservoir</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Efficiency Reservoir</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Efficiency Reservoir.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Efficiency Reservoir.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsEfficiencyReservoir_1.png"><img class="alignnone size-medium wp-image-3203" title="Rogue.Win32.WindowsEfficiencyReservoir" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsEfficiencyReservoir_1-400x234.png" alt="Rogue.Win32.WindowsEfficiencyReservoir" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsEfficiencyReservoir_2.png"><img class="alignnone size-medium wp-image-3204" title="Rogue.Win32.WindowsEfficiencyReservoir" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsEfficiencyReservoir_2-400x293.png" alt="Rogue.Win32.WindowsEfficiencyReservoir" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsEfficiencyReservoir_3.png"><img class="alignnone size-medium wp-image-3205" title="Rogue.Win32.WindowsEfficiencyReservoir" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsEfficiencyReservoir_3-400x293.png" alt="Rogue.Win32.WindowsEfficiencyReservoir" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsEfficiencyReservoir_4.png"><img class="alignnone size-medium wp-image-3206" title="Rogue.Win32.WindowsEfficiencyReservoir" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsEfficiencyReservoir_4-400x238.png" alt="Rogue.Win32.WindowsEfficiencyReservoir" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsEfficiencyReservoir_5.png"><img class="alignnone size-medium wp-image-3207" title="Rogue.Win32.WindowsEfficiencyReservoir" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsEfficiencyReservoir_5-400x253.png" alt="Rogue.Win32.WindowsEfficiencyReservoir" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Efficiency Reservoir </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsEfficiencyReservoir" target="_blank">Rogue.Win32.WindowsEfficiencyReservoir</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/25/windows-efficiency-accelerator-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Efficiency Accelerator Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Debugger Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/09/windows-efficiency-reservoir-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Care Taker Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/06/windows-care-taker-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/06/windows-care-taker-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 06 Apr 2012 03:31:24 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Care Taker]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3194</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Care Taker. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsCareTaker. Windows Care Taker is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Care Taker</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsCareTaker" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTaker" target="_blank"><strong>Rogue.Win32.WindowsCareTaker</strong></a><strong>.</strong></p>
<p><strong><strong><strong></strong></strong></strong><strong><strong><strong>Windows Care Taker</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Care Taker.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Care Taker.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCareTaker_1.png"><img class="alignnone size-medium wp-image-3195" title="Rogue.Win32.WindowsCareTaker" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCareTaker_1-400x234.png" alt="Rogue.Win32.WindowsCareTaker" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCareTaker_2.png"><img class="alignnone size-medium wp-image-3196" title="Rogue.Win32.WindowsCareTaker" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCareTaker_2-400x293.png" alt="Rogue.Win32.WindowsCareTaker" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCareTaker_3.png"><img class="alignnone size-medium wp-image-3197" title="Rogue.Win32.WindowsCareTaker" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCareTaker_3-400x293.png" alt="Rogue.Win32.WindowsCareTaker" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCareTaker_4.png"><img class="alignnone size-medium wp-image-3198" title="Rogue.Win32.WindowsCareTaker" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCareTaker_4-400x238.png" alt="Rogue.Win32.WindowsCareTaker" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCareTaker_5.png"><img class="alignnone size-medium wp-image-3199" title="Rogue.Win32.WindowsCareTaker" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCareTaker_5-400x253.png" alt="Rogue.Win32.WindowsCareTaker" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Care Taker </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCareTaker" target="_blank">Rogue.Win32.WindowsCareTaker</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/30/windows-trouble-taker-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Trouble Taker Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Debugger Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/06/windows-care-taker-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Custodian Utility Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/04/windows-custodian-utility-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/04/windows-custodian-utility-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 04 Apr 2012 11:36:53 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Custodian Utility]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3186</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Custodian Utility. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsCustodianUtility. Windows Custodian Utility is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Custodian Utility</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsCustodianUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustodianUtility" target="_blank"><strong>Rogue.Win32.WindowsCustodianUtility</strong></a><strong>.</strong></p>
<p><strong><strong><strong></strong></strong></strong><strong><strong><strong>Windows Custodian Utility</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Custodian Utility.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Custodian Utility.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCustodianUtility_1.png"><img class="alignnone size-medium wp-image-3187" title="Rogue.Win32.WindowsCustodianUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCustodianUtility_1-400x234.png" alt="Rogue.Win32.WindowsCustodianUtility" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCustodianUtility_3.png"><img class="alignnone size-medium wp-image-3189" title="Rogue.Win32.WindowsCustodianUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCustodianUtility_3-400x293.png" alt="Rogue.Win32.WindowsCustodianUtility" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCustodianUtility_4.png"><img class="alignnone size-medium wp-image-3190" title="Rogue.Win32.WindowsCustodianUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCustodianUtility_4-400x238.png" alt="Rogue.Win32.WindowsCustodianUtility" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCustodianUtility_5.png"><img class="alignnone size-medium wp-image-3191" title="Rogue.Win32.WindowsCustodianUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsCustodianUtility_5-400x253.png" alt="Rogue.Win32.WindowsCustodianUtility" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Custodian Utility </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsCustodianUtility" target="_blank">Rogue.Win32.WindowsCustodianUtility</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/03/windows-shielding-utility-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Shielding Utility Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Debugger Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/04/windows-custodian-utility-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Advanced Antispyware Solution Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/03/advanced-antispyware-solution-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/03/advanced-antispyware-solution-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 03 Apr 2012 19:42:29 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Advanced Antispyware Solution]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3178</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Advanced Antispyware Solution. Emsisoft Anti-Malware detects this malware as Rogue.Win32.AdvancedAntispywareSolution. Advanced Antispyware Solution is a rogue scanner application, another variant of Home Malware Cleaner, SmartAntiMalwareProtection, Antivirus Smart Protection, Malware Protection Center and Internet Security Guard. A rogue application tries to trick you by [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong>Advanced Antispyware Solution</strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.AdvancedAntispywareSolution" href="http://www.emsisoft.com/en/malware/?Adware.Win32.AdvancedAntispywareSolution" target="_blank"><strong>Rogue.Win32.AdvancedAntispywareSolution</strong></a><strong>.</strong></p>
<p><strong>Advanced Antispyware Solution </strong><strong></strong>is a rogue scanner application, another variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HomeMalwareCleaner"><strong>Home Malware Cleaner</strong></a>, <a title="Rogue.Win32.SmartAntiMalwareProtection" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartAntiMalwareProtection" target="_blank"><strong>SmartAntiMalwareProtection</strong></a><strong></strong>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirusSmartProtection"><strong>Antivirus Smart Protection</strong></a>, <a title="Malware Protection Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.MalwareProtectionCenter"><strong>Malware Protection Center</strong></a> and <a title="Rogue.Win32.InternetSecurityGuard" href="http://www.emsisoft.com/en/malware/?Adware.Win32.InternetSecurityGuard" target="_blank"><strong>Internet Security Guard</strong></a>. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Advanced Antispyware Solution</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\Advanced Antispyware Solution.lnk</li>
<li>%UserProfile%\Desktop\Advanced Antispyware Solution.lnk</li>
<li>%UserProfile%\Recent\ANTIGEN.sys</li>
<li>%UserProfile%\Recent\CLSV.dll</li>
<li>%UserProfile%\Recent\CLSV.drv</li>
<li>%UserProfile%\Recent\ddv.sys</li>
<li>%UserProfile%\Recent\dudl.tmp</li>
<li>%UserProfile%\Recent\eb.dll</li>
<li>%UserProfile%\Recent\energy.sys</li>
<li>%UserProfile%\Recent\exec.exe</li>
<li>%UserProfile%\Recent\FW.dll</li>
<li>%UserProfile%\Recent\grid.dll</li>
<li>%UserProfile%\Recent\hymt.sys</li>
<li>%UserProfile%\Recent\pal.dll</li>
<li>%UserProfile%\Recent\PE.dll</li>
<li>%UserProfile%\Recent\PE.drv</li>
<li>%UserProfile%\Recent\ppal.tmp</li>
<li>%UserProfile%\Recent\SM.tmp</li>
<li>%UserProfile%\Recent\tempdoc.tmp</li>
<li>%UserProfile%\Start Menu\Advanced Antispyware Solution.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Advanced Antispyware Solution.lnk</li>
<li>%AllUsersProfile%\Application Data\2a967e</li>
<li>%AllUsersProfile%\Application Data\2a967e\75.mof</li>
<li>%AllUsersProfile%\Application Data\2a967e\AA2a9_8010.exe</li>
<li>%AllUsersProfile%\Application Data\2a967e\AAS.ico</li>
<li>%AllUsersProfile%\Application Data\2a967e\aasolution.exe</li>
<li>%AllUsersProfile%\Application Data\2a967e\AASSys</li>
<li>%AllUsersProfile%\Application Data\2a967e\Quarantine Items</li>
<li>%AllUsersProfile%\Application Data\AAETFS</li>
<li>%AllUsersProfile%\Application Data\AAETFS\AALYASUAS.cfg</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\Classes\AA2a9_8010.DocHostUIHandler<br />
Default = Implements DocHostUIHandler<br />
Clsid  = {3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\Classes\clsid\{3F2BBC05-40DF-11D2-9455-00104BC936FF}<br />
Default = Implements DocHostUIHandler<br />
LocalServer32  = %AllUsersProfile%\Application Data\2a967e\AA2a9_8010.exe<br />
ProgID  = AA2a9_8010.DocHostUIHandler</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cl.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frmwrk32.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\homeav2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init32.exe \<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MalwareRemoval.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ozn695m5.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsAuxs.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsGui.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsSvc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsTray.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PC_Antispyware2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfndr.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PerAvir.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protector.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qh.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quick Heal.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\QuickHealCleaner.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Save.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveArmor.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveDefense.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveKeep.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secure Veteran.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\secureveteran.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Security Center.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SecurityFighter.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\securitysoldier.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smart.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartprotector.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smrtdefp.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftSafeness.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spywarexpguard.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrustWarrior.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\W3asbas.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windll32.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows Police Pro.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpdeluxe.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~1.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~2.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures = no<br />
RunInvalidSignatures = 01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\<br />
AAS = &#8220;%AllUsersProfile%\Application Data\2a967e\AA2a9_8010.exe&#8221; /s<br />
Advanced Antispyware Solution = &#8220;%AllUsersProfile%\Application Data\2a967e\AA2a9_8010.exe&#8221; /s /d</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.AdvancedAntispywareSolution_1.png"><img class="alignnone size-medium wp-image-3179" title="Rogue.Win32.AdvancedAntispywareSolution" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.AdvancedAntispywareSolution_1-400x202.png" alt="Rogue.Win32.AdvancedAntispywareSolution" width="400" height="202" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.AdvancedAntispywareSolution_2.png"><img class="alignnone size-medium wp-image-3180" title="Rogue.Win32.AdvancedAntispywareSolution" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.AdvancedAntispywareSolution_2-400x288.png" alt="Rogue.Win32.AdvancedAntispywareSolution" width="400" height="288" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.AdvancedAntispywareSolution_3.png"><img class="alignnone size-medium wp-image-3181" title="Rogue.Win32.AdvancedAntispywareSolution" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.AdvancedAntispywareSolution_3-400x288.png" alt="Rogue.Win32.AdvancedAntispywareSolution" width="400" height="288" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.AdvancedAntispywareSolution_4.png"><img class="alignnone size-medium wp-image-3182" title="Rogue.Win32.AdvancedAntispywareSolution" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.AdvancedAntispywareSolution_4-400x299.png" alt="Rogue.Win32.AdvancedAntispywareSolution" width="400" height="299" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><strong></strong><span style="color: #ff0000;"><strong>U2FD-S2LA-H4KA-UEPB</strong></span></pre>
<p><strong>How to remove the infection of Advanced Antispyware Solution </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AdvancedAntispywareSolution" target="_blank">Rogue.Win32.AdvancedAntispywareSolution</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/02/21/home-malware-cleaner-rogue-removal-instructions/" rel="bookmark" class="crp_title">Home Malware Cleaner Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Smart Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/02/15/smart-anti-malware-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Smart Anti-Malware Protection Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/03/advanced-antispyware-solution-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Shielding Utility Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/03/windows-shielding-utility-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/03/windows-shielding-utility-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 03 Apr 2012 09:39:09 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Shielding Utility]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3170</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Shielding Utility. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsShieldingUtility. Windows Shielding Utility is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Shielding Utility</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsShieldingUtility" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldingUtility" target="_blank"><strong>Rogue.Win32.WindowsShieldingUtility</strong></a><strong>.</strong></p>
<p><strong><strong><strong></strong></strong></strong><strong><strong><strong>Windows Shielding Utility</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Shielding Utility.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Shielding Utility.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsShieldingUtility_1.png"><img class="alignnone size-medium wp-image-3171" title="Rogue.Win32.WindowsShieldingUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsShieldingUtility_1-400x234.png" alt="Rogue.Win32.WindowsShieldingUtility" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsShieldingUtility_2.png"><img class="alignnone size-medium wp-image-3172" title="Rogue.Win32.WindowsShieldingUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsShieldingUtility_2-400x293.png" alt="Rogue.Win32.WindowsShieldingUtility" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsShieldingUtility_3.png"><img class="alignnone size-medium wp-image-3173" title="Rogue.Win32.WindowsShieldingUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsShieldingUtility_3-400x293.png" alt="Rogue.Win32.WindowsShieldingUtility" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsShieldingUtility_4.png"><img class="alignnone size-medium wp-image-3174" title="Rogue.Win32.WindowsShieldingUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsShieldingUtility_4-400x238.png" alt="Rogue.Win32.WindowsShieldingUtility" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsShieldingUtility_5.png"><img class="alignnone size-medium wp-image-3175" title="Rogue.Win32.WindowsShieldingUtility" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsShieldingUtility_5-400x253.png" alt="Rogue.Win32.WindowsShieldingUtility" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Shielding Utility </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldingUtility" target="_blank">Rogue.Win32.WindowsShieldingUtility</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/04/windows-custodian-utility-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Custodian Utility Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Debugger Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/03/windows-shielding-utility-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SMART HDD Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/02/smart-hdd-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/02/smart-hdd-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 02 Apr 2012 14:20:15 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[S.M.A.R.T HDD]]></category>
		<category><![CDATA[SMART HDD]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3164</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the SMART HDD. Emsisoft Anti-Malware detects this malware as Rogue.Win32.SmartHDD.b. SMART HDD (or S.M.A.R.T HDD) is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>SMART HDD</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.SmartHDD.b" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartHDD.b" target="_blank"><strong>Rogue.Win32.SmartHDD.b</strong></a><strong>.</strong></p>
<p><strong><strong><strong>SMART HDD </strong></strong></strong>(or <strong>S.M.A.R.T HDD</strong>) is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\-ch1+6T~]V&amp;zN,</li>
<li>%AllUsersProfile%\Application Data\-ch1+6T~]V&amp;zN,r</li>
<li>%AllUsersProfile%\Application Data\ch1+6T~]V&amp;zN,</li>
<li>%AllUsersProfile%\Application Data\ch1+6T~]V&amp;zN,.exe</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\SMART_HDD.lnk</li>
<li>%UserProfile%\Desktop\SMART_HDD.lnk</li>
<li>%UserProfile%\Desktop\SMART_HDD_License.txt</li>
<li>%UserProfile%\Start Menu\Programs\SMART HDD\</li>
<li>%UserProfile%\Start Menu\Programs\SMART HDD\SMART HDD.lnk</li>
<li>%UserProfile%\Start Menu\Programs\SMART HDD\Uninstall SMART HDD.lnk</li>
</ul>
<p><strong>Create / modify registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER|\Software\Microsoft\Windows\CurrentVersion\Run<br />
ch1+6T~]V&amp;zN, = %AllUsersProfile%\Application Data\ch1+6T~]V&amp;zN,.exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Main\<br />
Use FormSuggest = Yes</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings<br />
WarnOnZoneCrossing = 0&#215;00000000<br />
WarnonBadCertRecving = 0&#215;00000000<br />
CertificateRevocation = 0&#215;00000000</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.SmartHDD.b_1.png"><img class="alignnone size-medium wp-image-3165" title="Rogue.Win32.SmartHDD.b" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.SmartHDD.b_1-400x331.png" alt="Rogue.Win32.SmartHDD.b" width="400" height="331" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.SmartHDD.b_2.png"><img class="alignnone size-medium wp-image-3166" title="Rogue.Win32.SmartHDD.b" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.SmartHDD.b_2-400x240.png" alt="Rogue.Win32.SmartHDD.b" width="400" height="240" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.SmartHDD.b_3.png"><img class="alignnone size-medium wp-image-3167" title="Rogue.Win32.SmartHDD.b" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.SmartHDD.b_3-400x175.png" alt="Rogue.Win32.SmartHDD.b" width="400" height="175" /></a></p>
<p>To register this rogue application you can try the following serial number and enter any email:</p>
<pre><span style="color: #ff0000;"><strong>15801587234612645205224631045976</strong></span>
<strong></strong></pre>
<p><strong>How to remove the infection of SMART HDD</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartHDD.b" target="_blank">Rogue.Win32.SmartHDD.b</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2010/12/16/smart-hdd-adware-removal-instructions/" rel="bookmark" class="crp_title">Smart HDD Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/23/smart-protection-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Smart Protection 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/02/29/smart-fortress-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Smart Fortress 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/23/internet-security-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/01/10/my-disk-adware-removal-instructions/" rel="bookmark" class="crp_title">My Disk Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/02/smart-hdd-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Warding System Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/02/windows-warding-system-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/02/windows-warding-system-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 02 Apr 2012 13:29:20 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Warding System]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3157</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Warding System. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsWardingSystem. Windows Warding System is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Warding System</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsWardingSystem" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWardingSystem" target="_blank"><strong>Rogue.Win32.WindowsWardingSystem</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Warding System</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Warding System.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Warding System.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsWardingSystem_1.png"><img class="alignnone size-medium wp-image-3158" title="Rogue.Win32.WindowsWardingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsWardingSystem_1-400x234.png" alt="Rogue.Win32.WindowsWardingSystem" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsWardingSystem_2.png"><img class="alignnone size-medium wp-image-3159" title="Rogue.Win32.WindowsWardingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsWardingSystem_2-400x293.png" alt="Rogue.Win32.WindowsWardingSystem" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsWardingSystem_3.png"><img class="alignnone size-medium wp-image-3160" title="Rogue.Win32.WindowsWardingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsWardingSystem_3-400x293.png" alt="Rogue.Win32.WindowsWardingSystem" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsWardingSystem_4.png"><img class="alignnone size-medium wp-image-3161" title="Rogue.Win32.WindowsWardingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsWardingSystem_4-400x238.png" alt="Rogue.Win32.WindowsWardingSystem" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsWardingSystem_5.png"><img class="alignnone size-medium wp-image-3162" title="Rogue.Win32.WindowsWardingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsWardingSystem_5-400x253.png" alt="Rogue.Win32.WindowsWardingSystem" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Warding System </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsWardingSystem" target="_blank">Rogue.Win32.WindowsWardingSystem</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/11/windows-antibreaking-system-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Antibreaking System Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Debugger Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/02/windows-warding-system-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows First-Class Protector Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 02 Apr 2012 13:23:12 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows First-Class Protector]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3149</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows First-Class Protector. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsFirstClassProtector. Windows First-Class Protector is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows First-Class Protector</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsFirstClassProtector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirstClassProtector" target="_blank"><strong>Rogue.Win32.WindowsFirstClassProtector</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows First-Class Protector</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows First-Class Protector.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows First-Class Protector.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsFirstClassProtector_2.png"><img class="alignnone size-medium wp-image-3150" title="Rogue.Win32.WindowsFirstClassProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsFirstClassProtector_2-400x234.png" alt="Rogue.Win32.WindowsFirstClassProtector" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsFirstClassProtector_3.png"><img class="alignnone size-medium wp-image-3151" title="Rogue.Win32.WindowsFirstClassProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsFirstClassProtector_3-400x293.png" alt="Rogue.Win32.WindowsFirstClassProtector" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsFirstClassProtector_4.png"><img class="alignnone size-medium wp-image-3152" title="Rogue.Win32.WindowsFirstClassProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsFirstClassProtector_4-400x293.png" alt="Rogue.Win32.WindowsFirstClassProtector" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsFirstClassProtector_5.png"><img class="alignnone size-medium wp-image-3153" title="Rogue.Win32.WindowsFirstClassProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsFirstClassProtector_5-400x238.png" alt="Rogue.Win32.WindowsFirstClassProtector" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsFirstClassProtector_6.png"><img class="alignnone size-medium wp-image-3154" title="Rogue.Win32.WindowsFirstClassProtector" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsFirstClassProtector_6-400x253.png" alt="Rogue.Win32.WindowsFirstClassProtector" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows First-Class Protector </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirstClassProtector" target="_blank">Rogue.Win32.WindowsFirstClassProtector</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/20/windows-foolproof-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Foolproof Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/10/windows-component-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Component Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Debugger Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Activity Debugger Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 02 Apr 2012 13:05:24 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Activity Debugger]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3142</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Activity Debugger. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsActivityDebugger. Windows Activity Debugger is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Activity Debugger</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsActivityDebugger" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityDebugger" target="_blank"><strong>Rogue.Win32.WindowsActivityDebugger</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Activity Debugger</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Activity Debugger.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Activity Debugger.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsActivityDebugger_1.png"><img class="alignnone size-medium wp-image-3143" title="Rogue.Win32.WindowsActivityDebugger" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsActivityDebugger_1-400x234.png" alt="Rogue.Win32.WindowsActivityDebugger" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsActivityDebugger_2.png"><img class="alignnone size-medium wp-image-3144" title="Rogue.Win32.WindowsActivityDebugger" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsActivityDebugger_2-400x293.png" alt="Rogue.Win32.WindowsActivityDebugger" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsActivityDebugger_3.png"><img class="alignnone size-medium wp-image-3145" title="Rogue.Win32.WindowsActivityDebugger" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsActivityDebugger_3-400x293.png" alt="Rogue.Win32.WindowsActivityDebugger" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsActivityDebugger_4.png"><img class="alignnone size-medium wp-image-3146" title="Rogue.Win32.WindowsActivityDebugger" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsActivityDebugger_4-400x238.png" alt="Rogue.Win32.WindowsActivityDebugger" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsActivityDebugger_5.png"><img class="alignnone size-medium wp-image-3147" title="Rogue.Win32.WindowsActivityDebugger" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/04/Rogue.Win32.WindowsActivityDebugger_5-400x253.png" alt="Rogue.Win32.WindowsActivityDebugger" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Activity Debugger </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsActivityDebugger" target="_blank">Rogue.Win32.WindowsActivityDebugger</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/04/windows-custodian-utility-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Custodian Utility Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/20/windows-foolproof-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Foolproof Protector Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Trouble Taker Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/30/windows-trouble-taker-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/30/windows-trouble-taker-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 30 Mar 2012 09:37:18 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Trouble Taker]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3134</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Trouble Taker. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsTroubleTaker. Windows Trouble Taker is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Trouble Taker</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsTroubleTaker" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroubleTaker" target="_blank"><strong>Rogue.Win32.WindowsTroubleTaker</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Trouble Taker</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Trouble Taker.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Trouble Taker.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsTroubleTaker_1.png"><img class="alignnone size-medium wp-image-3135" title="Rogue.Win32.WindowsTroubleTaker" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsTroubleTaker_1-400x234.png" alt="Rogue.Win32.WindowsTroubleTaker" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsTroubleTaker_2.png"><img class="alignnone size-medium wp-image-3136" title="Rogue.Win32.WindowsTroubleTaker" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsTroubleTaker_2-400x293.png" alt="Rogue.Win32.WindowsTroubleTaker" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsTroubleTaker_3.png"><img class="alignnone size-medium wp-image-3137" title="Rogue.Win32.WindowsTroubleTaker" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsTroubleTaker_3-400x293.png" alt="Rogue.Win32.WindowsTroubleTaker" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsTroubleTaker_4.png"><img class="alignnone size-medium wp-image-3138" title="Rogue.Win32.WindowsTroubleTaker" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsTroubleTaker_4-400x238.png" alt="Rogue.Win32.WindowsTroubleTaker" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsTroubleTaker_5.png"><img class="alignnone size-medium wp-image-3139" title="Rogue.Win32.WindowsTroubleTaker" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsTroubleTaker_5-400x253.png" alt="Rogue.Win32.WindowsTroubleTaker" width="400" height="253" /></a></p>
<p>To register this rogue application you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Trouble Taker </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTroubleTaker" target="_blank">Rogue.Win32.WindowsTroubleTaker</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/06/windows-care-taker-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Care Taker Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Debugger Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/30/windows-trouble-taker-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Defending Center Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/28/windows-defending-center-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/28/windows-defending-center-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 28 Mar 2012 08:49:31 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Defending Center]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3125</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Defending Center. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsDefendingCenter. Windows Defending Center is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Defending Center</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsDefendingCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefendingCenter" target="_blank"><strong>Rogue.Win32.WindowsDefendingCenter</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Defending Center</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Defending Center.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Defending Center.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsDefendingCenter_0.png"><img class="alignnone size-medium wp-image-3126" title="Rogue.Win32.WindowsDefendingCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsDefendingCenter_0-400x276.png" alt="Rogue.Win32.WindowsDefendingCenter" width="400" height="276" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsDefendingCenter_1.png"><img class="alignnone size-medium wp-image-3127" title="Rogue.Win32.WindowsDefendingCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsDefendingCenter_1-400x234.png" alt="Rogue.Win32.WindowsDefendingCenter" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsDefendingCenter_3.png"><img class="alignnone size-medium wp-image-3128" title="Rogue.Win32.WindowsDefendingCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsDefendingCenter_3-400x293.png" alt="Rogue.Win32.WindowsDefendingCenter" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsDefendingCenter_4.png"><img class="alignnone size-medium wp-image-3129" title="Rogue.Win32.WindowsDefendingCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsDefendingCenter_4-400x238.png" alt="Rogue.Win32.WindowsDefendingCenter" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsDefendingCenter_5.png"><img class="alignnone size-medium wp-image-3130" title="Rogue.Win32.WindowsDefendingCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsDefendingCenter_5-400x253.png" alt="Rogue.Win32.WindowsDefendingCenter" width="400" height="253" /></a></p>
<p>To register this rogue application, you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>0W000-000B0-00T00-E0020</strong></span></pre>
<p><strong>How to remove the infection of Windows Defending Center </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDefendingCenter" target="_blank">Rogue.Win32.WindowsDefendingCenter</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/05/10/windows-pro-solutions-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Solutions Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-first-class-protector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows First-Class Protector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-activity-debugger-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Activity Debugger Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-debug-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Debug Center Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/28/windows-defending-center-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows No-Risk Agent Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/27/windows-no-risk-agent-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/27/windows-no-risk-agent-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 27 Mar 2012 13:14:32 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows No-Risk Agent]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3118</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows No-Risk Agent. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsNoRiskAgent. Windows No-Risk Agent is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows No-Risk Agent</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsNoRiskAgent" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsNoRiskAgent" target="_blank"><strong>Rogue.Win32.WindowsNoRiskAgent</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows No-Risk Agent</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows No-Risk Agent.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows No-Risk Agent.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsNoRiskAgent_1.png"><img class="alignnone size-medium wp-image-3119" title="Rogue.Win32.WindowsNoRiskAgent" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsNoRiskAgent_1-400x234.png" alt="Rogue.Win32.WindowsNoRiskAgent" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsNoRiskAgent_2.png"><img class="alignnone size-medium wp-image-3120" title="Rogue.Win32.WindowsNoRiskAgent" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsNoRiskAgent_2-400x293.png" alt="Rogue.Win32.WindowsNoRiskAgent" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsNoRiskAgent_3.png"><img class="alignnone size-medium wp-image-3121" title="Rogue.Win32.WindowsNoRiskAgent" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsNoRiskAgent_3-400x293.png" alt="Rogue.Win32.WindowsNoRiskAgent" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsNoRiskAgent_4.png"><img class="alignnone size-medium wp-image-3122" title="Rogue.Win32.WindowsNoRiskAgent" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsNoRiskAgent_4-400x238.png" alt="Rogue.Win32.WindowsNoRiskAgent" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsNoRiskAgent_5.png"><img class="alignnone size-medium wp-image-3123" title="Rogue.Win32.WindowsNoRiskAgent" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsNoRiskAgent_5-400x253.png" alt="Rogue.Win32.WindowsNoRiskAgent" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows No-Risk Agent </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsNoRiskAgent" target="_blank">Rogue.Win32.WindowsNoRiskAgent</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-no-risk-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows No-Risk Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-trojans-inspector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Trojans Inspector Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/27/windows-no-risk-agent-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Debug Center Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/27/windows-debug-center-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/27/windows-debug-center-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 27 Mar 2012 07:09:06 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Debug Center]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3110</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Debug Center. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsDebugCenter. Windows Debug Center is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Debug Center</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsDebugCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDebugCenter" target="_blank"><strong>Rogue.Win32.WindowsDebugCenter</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Debug Center</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Debug Center.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Debug Center.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsDebugCenter_1.png"><img class="alignnone size-medium wp-image-3111" title="Rogue.Win32.WindowsDebugCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsDebugCenter_1-400x234.png" alt="Rogue.Win32.WindowsDebugCenter" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsDebugCenter_2.png"><img class="alignnone size-medium wp-image-3112" title="Rogue.Win32.WindowsDebugCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsDebugCenter_2-400x293.png" alt="Rogue.Win32.WindowsDebugCenter" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsDebugCenter_3.png"><img class="alignnone size-medium wp-image-3113" title="Rogue.Win32.WindowsDebugCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsDebugCenter_3-400x293.png" alt="Rogue.Win32.WindowsDebugCenter" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsDebugCenter_4.png"><img class="alignnone size-medium wp-image-3114" title="Rogue.Win32.WindowsDebugCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsDebugCenter_4-400x238.png" alt="Rogue.Win32.WindowsDebugCenter" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsDebugCenter_5.png"><img class="alignnone size-medium wp-image-3115" title="Rogue.Win32.WindowsDebugCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsDebugCenter_5-400x253.png" alt="Rogue.Win32.WindowsDebugCenter" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Debug Center </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsDebugCenter" target="_blank">Rogue.Win32.WindowsDebugCenter</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/23/windows-antihazard-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Antihazard Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-no-risk-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows No-Risk Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/27/windows-debug-center-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows AntiHazard Helper Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/27/windows-antihazard-helper-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/27/windows-antihazard-helper-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 27 Mar 2012 06:58:53 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows AntiHazard Helper]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3102</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows AntiHazard Helper. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsAntiHazardHelper. Windows AntiHazard Helper is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows AntiHazard Helper</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsAntiHazardHelper" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntiHazardHelper" target="_blank"><strong>Rogue.Win32.WindowsAntiHazardHelper</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows AntiHazard Helper</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows AntiHazard Helper.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows AntiHazard Helper.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntiHazardHelper_1.png"><img class="alignnone size-medium wp-image-3103" title="Rogue.Win32.WindowsAntiHazardHelper" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntiHazardHelper_1-400x234.png" alt="Rogue.Win32.WindowsAntiHazardHelper" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntiHazardHelper_2.png"><img class="alignnone size-medium wp-image-3104" title="Rogue.Win32.WindowsAntiHazardHelper" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntiHazardHelper_2-400x293.png" alt="Rogue.Win32.WindowsAntiHazardHelper" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntiHazardHelper_3.png"><img class="alignnone size-medium wp-image-3105" title="Rogue.Win32.WindowsAntiHazardHelper" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntiHazardHelper_3-400x293.png" alt="Rogue.Win32.WindowsAntiHazardHelper" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntiHazardHelper_4.png"><img class="alignnone size-medium wp-image-3106" title="Rogue.Win32.WindowsAntiHazardHelper" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntiHazardHelper_4-400x238.png" alt="Rogue.Win32.WindowsAntiHazardHelper" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntiHazardHelper_5.png"><img class="alignnone size-medium wp-image-3107" title="Rogue.Win32.WindowsAntiHazardHelper" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntiHazardHelper_5-400x253.png" alt="Rogue.Win32.WindowsAntiHazardHelper" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows AntiHazard Helper </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntiHazardHelper" target="_blank">Rogue.Win32.WindowsAntiHazardHelper</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/23/windows-antihazard-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Antihazard Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-pro-web-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Pro Web Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/16/windows-antihazard-solution-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Antihazard Solution Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/27/windows-antihazard-helper-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Software Saver Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 26 Mar 2012 08:20:50 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Software Saver]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3094</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Software Saver. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsSoftwareSaver. Windows Software Saver is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Windows Software Saver</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsSoftwareSaver" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareSaver" target="_blank"><strong>Rogue.Win32.WindowsSoftwareSaver</strong></a><strong>.</strong></p>
<p><strong><strong><strong>Windows Software Saver</strong></strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Software Saver.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Software Saver.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsSoftwareSaver_1.png"><img class="alignnone size-medium wp-image-3095" title="Rogue.Win32.WindowsSoftwareSaver" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsSoftwareSaver_1-400x234.png" alt="Rogue.Win32.WindowsSoftwareSaver" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsSoftwareSaver_2.png"><img class="alignnone size-medium wp-image-3096" title="Rogue.Win32.WindowsSoftwareSaver" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsSoftwareSaver_2-400x293.png" alt="Rogue.Win32.WindowsSoftwareSaver" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsSoftwareSaver_3.png"><img class="alignnone size-medium wp-image-3097" title="Rogue.Win32.WindowsSoftwareSaver" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsSoftwareSaver_3-400x293.png" alt="Rogue.Win32.WindowsSoftwareSaver" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsSoftwareSaver_4.png"><img class="alignnone size-medium wp-image-3098" title="Rogue.Win32.WindowsSoftwareSaver" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsSoftwareSaver_4-400x238.png" alt="Rogue.Win32.WindowsSoftwareSaver" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsSoftwareSaver_5.png"><img class="alignnone size-medium wp-image-3099" title="Rogue.Win32.WindowsSoftwareSaver" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsSoftwareSaver_5-400x253.png" alt="Rogue.Win32.WindowsSoftwareSaver" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Software Saver </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareSaver" target="_blank">Rogue.Win32.WindowsSoftwareSaver</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-trojans-inspector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Trojans Inspector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-no-risk-agent-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows No-Risk Agent Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/02/windows-attacks-defender-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Attacks Defender Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Antihazard Center Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/23/windows-antihazard-center-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/23/windows-antihazard-center-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 23 Mar 2012 11:50:01 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows AntiHazard Center]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3086</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows AntiHazard Center. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsAntiHazardCenter. Windows AntiHazard Center is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong>Windows AntiHazard Center</strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsAntiHazardCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntiHazardCenter" target="_blank"><strong>Rogue.Win32.WindowsAntiHazardCenter</strong></a><strong>.</strong></p>
<p><strong><strong>Windows AntiHazard Center</strong></strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows AntiHazard Center.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows AntiHazard Center.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntihazardCenter_1.png"><img class="alignnone size-medium wp-image-3087" title="Rogue.Win32.WindowsAntihazardCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntihazardCenter_1-400x234.png" alt="Rogue.Win32.WindowsAntihazardCenter" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntihazardCenter_2.png"><img class="alignnone size-medium wp-image-3088" title="Rogue.Win32.WindowsAntihazardCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntihazardCenter_2-400x293.png" alt="Rogue.Win32.WindowsAntihazardCenter" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntihazardCenter_3.png"><img class="alignnone size-medium wp-image-3089" title="Rogue.Win32.WindowsAntihazardCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntihazardCenter_3-400x293.png" alt="Rogue.Win32.WindowsAntihazardCenter" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntihazardCenter_4.png"><img class="alignnone size-medium wp-image-3090" title="Rogue.Win32.WindowsAntihazardCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntihazardCenter_4-400x238.png" alt="Rogue.Win32.WindowsAntihazardCenter" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntihazardCenter_5.png"><img class="alignnone size-medium wp-image-3091" title="Rogue.Win32.WindowsAntihazardCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntihazardCenter_5-400x253.png" alt="Rogue.Win32.WindowsAntihazardCenter" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows AntiHazard Center </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntiHazardCenter" target="_blank">Rogue.Win32.WindowsAntiHazardCenter</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-antihazard-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows AntiHazard Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/16/windows-antihazard-solution-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Antihazard Solution Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-debug-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Debug Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-no-risk-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows No-Risk Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/23/windows-antihazard-center-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Process Director Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/22/windows-process-director-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/22/windows-process-director-rogue-removal-instructions/#comments</comments>
		<pubDate>Thu, 22 Mar 2012 08:03:14 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Process Director]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3079</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Process Director. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsProcessDirector. Windows Process Director is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Process Director</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsProcessDirector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessDirector" target="_blank"><strong>Rogue.Win32.WindowsProcessDirector</strong></a><strong>.</strong></p>
<p><strong>Windows Process Director</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Process Director.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Process Director.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsProcessDirector_1.png"><img class="alignnone size-medium wp-image-3080" title="Rogue.Win32.WindowsProcessDirector" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsProcessDirector_1-400x234.png" alt="Rogue.Win32.WindowsProcessDirector" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsProcessDirector_2.png"><img class="alignnone size-medium wp-image-3081" title="Rogue.Win32.WindowsProcessDirector" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsProcessDirector_2-400x293.png" alt="Rogue.Win32.WindowsProcessDirector" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsProcessDirector_3.png"><img class="alignnone size-medium wp-image-3082" title="Rogue.Win32.WindowsProcessDirector" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsProcessDirector_3-400x293.png" alt="Rogue.Win32.WindowsProcessDirector" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsProcessDirector_4.png"><img class="alignnone size-medium wp-image-3083" title="Rogue.Win32.WindowsProcessDirector" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsProcessDirector_4-400x238.png" alt="Rogue.Win32.WindowsProcessDirector" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsProcessDirector_5.png"><img class="alignnone size-medium wp-image-3084" title="Rogue.Win32.WindowsProcessDirector" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsProcessDirector_5-400x253.png" alt="Rogue.Win32.WindowsProcessDirector" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Process Director </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProcessDirector" target="_blank">Rogue.Win32.WindowsProcessDirector</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-trojans-inspector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Trojans Inspector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-no-risk-agent-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows No-Risk Agent Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/22/windows-process-director-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Guardian Angel Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/21/windows-guardian-angel-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/21/windows-guardian-angel-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 21 Mar 2012 14:42:05 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Guardian Angel]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3070</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Guardian Angel. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsGuardianAngel. Windows Guardian Angel is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Guardian Angel</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsGuardianAngel" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsGuardianAngel" target="_blank"><strong>Rogue.Win32.WindowsGuardianAngel</strong></a><strong>.</strong></p>
<p><strong>Windows Guardian Angel</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Guardian Angel.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Guardian Angel.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsGuardianAngel_1.png"><img class="alignnone size-medium wp-image-3071" title="Rogue.Win32.WindowsGuardianAngel" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsGuardianAngel_1-400x234.png" alt="Rogue.Win32.WindowsGuardianAngel" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsGuardianAngel_2.png"><img class="alignnone size-medium wp-image-3072" title="Rogue.Win32.WindowsGuardianAngel" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsGuardianAngel_2-400x293.png" alt="Rogue.Win32.WindowsGuardianAngel" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsGuardianAngel_3.png"><img class="alignnone size-medium wp-image-3073" title="Rogue.Win32.WindowsGuardianAngel" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsGuardianAngel_3-400x293.png" alt="Rogue.Win32.WindowsGuardianAngel" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsGuardianAngel_4.png"><img class="alignnone size-medium wp-image-3074" title="Rogue.Win32.WindowsGuardianAngel" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsGuardianAngel_4-400x238.png" alt="Rogue.Win32.WindowsGuardianAngel" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsGuardianAngel_5.png"><img class="alignnone size-medium wp-image-3075" title="Rogue.Win32.WindowsGuardianAngel" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsGuardianAngel_5-400x253.png" alt="Rogue.Win32.WindowsGuardianAngel" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Guardian Angel </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsGuardianAngel" target="_blank">Rogue.Win32.WindowsGuardianAngel</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-trojans-inspector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Trojans Inspector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-no-risk-agent-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows No-Risk Agent Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/21/windows-guardian-angel-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows No-Risk Center Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/20/windows-no-risk-center-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/20/windows-no-risk-center-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 20 Mar 2012 06:19:53 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows No-Risk Center]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3063</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows No-Risk Center. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsNoRiskCenter. Windows No-Risk Center is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows No-Risk Center</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsNoRiskCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsNoRiskCenter" target="_blank"><strong>Rogue.Win32.WindowsNoRiskCenter</strong></a><strong>.</strong></p>
<p><strong>Windows No-Risk Center</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows No-Risk Center.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows No-Risk Center.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsNoRiskCenter_1.png"><img class="alignnone size-medium wp-image-3064" title="Rogue.Win32.WindowsNoRiskCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsNoRiskCenter_1-400x234.png" alt="Rogue.Win32.WindowsNoRiskCenter" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsNoRiskCenter_2.png"><img class="alignnone size-medium wp-image-3065" title="Rogue.Win32.WindowsNoRiskCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsNoRiskCenter_2-400x293.png" alt="Rogue.Win32.WindowsNoRiskCenter" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsNoRiskCenter_3.png"><img class="alignnone size-medium wp-image-3066" title="Rogue.Win32.WindowsNoRiskCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsNoRiskCenter_3-400x293.png" alt="Rogue.Win32.WindowsNoRiskCenter" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsNoRiskCenter_4.png"><img class="alignnone size-medium wp-image-3067" title="Rogue.Win32.WindowsNoRiskCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsNoRiskCenter_4-400x238.png" alt="Rogue.Win32.WindowsNoRiskCenter" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsNoRiskCenter_5.png"><img class="alignnone size-medium wp-image-3068" title="Rogue.Win32.WindowsNoRiskCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsNoRiskCenter_5-400x253.png" alt="Rogue.Win32.WindowsNoRiskCenter" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows No-Risk Center </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsNoRiskCenter" target="_blank">Rogue.Win32.WindowsNoRiskCenter</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-no-risk-agent-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows No-Risk Agent Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-debug-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Debug Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/23/windows-antihazard-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Antihazard Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/20/windows-no-risk-center-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Software Keeper Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 20 Mar 2012 06:02:55 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Software Keeper]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3056</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Software Keeper. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsSoftwareKeeper. Windows Software Keeper is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Software Keeper</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsSoftwareKeeper" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareKeeper" target="_blank"><strong>Rogue.Win32.WindowsSoftwareKeeper</strong></a><strong>.</strong></p>
<p><strong>Windows Software Keeper</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Software Keeper.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Software Keeper.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsSoftwareKeeper_1.png"><img class="alignnone size-medium wp-image-3057" title="Rogue.Win32.WindowsSoftwareKeeper" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsSoftwareKeeper_1-400x234.png" alt="Rogue.Win32.WindowsSoftwareKeeper" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsSoftwareKeeper_2.png"><img class="alignnone size-medium wp-image-3058" title="Rogue.Win32.WindowsSoftwareKeeper" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsSoftwareKeeper_2-400x293.png" alt="Rogue.Win32.WindowsSoftwareKeeper" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsSoftwareKeeper_3.png"><img class="alignnone size-medium wp-image-3059" title="Rogue.Win32.WindowsSoftwareKeeper" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsSoftwareKeeper_3-400x293.png" alt="Rogue.Win32.WindowsSoftwareKeeper" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsSoftwareKeeper_4.png"><img class="alignnone size-medium wp-image-3060" title="Rogue.Win32.WindowsSoftwareKeeper" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsSoftwareKeeper_4-400x238.png" alt="Rogue.Win32.WindowsSoftwareKeeper" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsSoftwareKeeper_5.png"><img class="alignnone size-medium wp-image-3061" title="Rogue.Win32.WindowsSoftwareKeeper" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsSoftwareKeeper_5-400x253.png" alt="Rogue.Win32.WindowsSoftwareKeeper" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Software Keeper </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSoftwareKeeper" target="_blank">Rogue.Win32.WindowsSoftwareKeeper</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-trojans-inspector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Trojans Inspector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-no-risk-agent-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows No-Risk Agent Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/02/windows-attacks-defender-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Attacks Defender Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Problems Stopper Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/19/windows-problems-stopper-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/19/windows-problems-stopper-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 19 Mar 2012 08:22:56 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Problems Stopper]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3049</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Problems Stopper. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsProblemsStopper. Windows Problems Stopper is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Problems Stopper</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsProblemsStopper" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsStopper" target="_blank"><strong>Rogue.Win32.WindowsProblemsStopper</strong></a><strong>.</strong></p>
<p><strong>Windows Problems Stopper</strong> is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Problems Stopper.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Problems Stopper.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsProblemsStopper_1.png"><img class="alignnone size-medium wp-image-3050" title="Rogue.Win32.WindowsProblemsStopper" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsProblemsStopper_1-400x234.png" alt="Rogue.Win32.WindowsProblemsStopper" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsProblemsStopper_2.png"><img class="alignnone size-medium wp-image-3051" title="Rogue.Win32.WindowsProblemsStopper" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsProblemsStopper_2-400x293.png" alt="Rogue.Win32.WindowsProblemsStopper" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsProblemsStopper_3.png"><img class="alignnone size-medium wp-image-3052" title="Rogue.Win32.WindowsProblemsStopper" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsProblemsStopper_3-400x293.png" alt="Rogue.Win32.WindowsProblemsStopper" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsProblemsStopper_4.png"><img class="alignnone size-medium wp-image-3053" title="Rogue.Win32.WindowsProblemsStopper" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsProblemsStopper_4-400x238.png" alt="Rogue.Win32.WindowsProblemsStopper" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsProblemsStopper_5.png"><img class="alignnone size-medium wp-image-3054" title="Rogue.Win32.WindowsProblemsStopper" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsProblemsStopper_5-400x253.png" alt="Rogue.Win32.WindowsProblemsStopper" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Problems Stopper </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProblemsStopper" target="_blank">Rogue.Win32.WindowsProblemsStopper</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-trojans-inspector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Trojans Inspector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-no-risk-agent-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows No-Risk Agent Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/19/windows-problems-stopper-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Antihazard Solution Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/16/windows-antihazard-solution-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/16/windows-antihazard-solution-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 16 Mar 2012 11:42:27 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Antihazard Solution]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3040</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Antihazard Solution. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsAntihazardSolution. Windows Antihazard Solution is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong></strong><strong>Windows Antihazard Solution</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsAntihazardSolution" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntihazardSolution" target="_blank"><strong>Rogue.Win32.WindowsAntihazardSolution</strong></a><strong>.</strong></p>
<p><strong></strong><strong><strong>Windows Antihazard Solution</strong></strong> <strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%UserProfile%\Local Settings\Application Data\Protector-[random].exe</li>
<li>%UserProfile%\Local Settings\Application Data\result.db</li>
<li>%UserProfile%\Desktop\Windows Antihazard Solution.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Antihazard Solution.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %UserProfile%\Local Settings\Application Data\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntihazardSolution_1.png"><img class="alignnone size-medium wp-image-3041" title="Rogue.Win32.WindowsAntihazardSolution" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntihazardSolution_1-400x234.png" alt="Rogue.Win32.WindowsAntihazardSolution" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntihazardSolution_2.png"><img class="alignnone size-medium wp-image-3042" title="Rogue.Win32.WindowsAntihazardSolution" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntihazardSolution_2-400x293.png" alt="Rogue.Win32.WindowsAntihazardSolution" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntihazardSolution_3.png"><img class="alignnone size-medium wp-image-3043" title="Rogue.Win32.WindowsAntihazardSolution" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntihazardSolution_3-400x293.png" alt="Rogue.Win32.WindowsAntihazardSolution" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntihazardSolution_4.png"><img class="alignnone size-medium wp-image-3044" title="Rogue.Win32.WindowsAntihazardSolution" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntihazardSolution_4-400x238.png" alt="Rogue.Win32.WindowsAntihazardSolution" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntihazardSolution_5.png"><img class="alignnone size-medium wp-image-3045" title="Rogue.Win32.WindowsAntihazardSolution" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAntihazardSolution_5-400x253.png" alt="Rogue.Win32.WindowsAntihazardSolution" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Antihazard Solution </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAntihazardSolution" target="_blank">Rogue.Win32.WindowsAntihazardSolution</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-antihazard-helper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows AntiHazard Helper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/23/windows-antihazard-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Antihazard Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/16/windows-antihazard-solution-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Risk Minimizer Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/15/windows-risk-minimizer-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/15/windows-risk-minimizer-rogue-removal-instructions/#comments</comments>
		<pubDate>Thu, 15 Mar 2012 15:03:11 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Risk Minimizer]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3031</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Risk Minimizer. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsRiskMinimizer. Windows Risk Minimizer is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Risk Minimizer</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsRiskMinimizer" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskMinimizer" target="_blank"><strong>Rogue.Win32.WindowsRiskMinimizer</strong></a><strong>.</strong></p>
<p><strong></strong><strong>Windows Risk Minimizer</strong> <strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%UserProfile%\Local Settings\Application Data\Protector-[random].exe</li>
<li>%UserProfile%\Local Settings\Application Data\result.db</li>
<li>%UserProfile%\Desktop\Windows Risk Minimizer.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Risk Minimizer.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %UserProfile%\Local Settings\Application Data\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsRiskMinimizer_1.png"><img class="alignnone size-medium wp-image-3032" title="Rogue.Win32.WindowsRiskMinimizer" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsRiskMinimizer_1-400x234.png" alt="Rogue.Win32.WindowsRiskMinimizer" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsRiskMinimizer_2.png"><img class="alignnone size-medium wp-image-3033" title="Rogue.Win32.WindowsRiskMinimizer" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsRiskMinimizer_2-400x293.png" alt="Rogue.Win32.WindowsRiskMinimizer" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsRiskMinimizer_3.png"><img class="alignnone size-medium wp-image-3034" title="Rogue.Win32.WindowsRiskMinimizer" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsRiskMinimizer_3-400x293.png" alt="Rogue.Win32.WindowsRiskMinimizer" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsRiskMinimizer_4.png"><img class="alignnone size-medium wp-image-3035" title="Rogue.Win32.WindowsRiskMinimizer" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsRiskMinimizer_4-400x238.png" alt="Rogue.Win32.WindowsRiskMinimizer" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsRiskMinimizer_5.png"><img class="alignnone size-medium wp-image-3036" title="Rogue.Win32.WindowsRiskMinimizer" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsRiskMinimizer_5-400x253.png" alt="Rogue.Win32.WindowsRiskMinimizer" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Risk Minimizer  </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsRiskMinimizer" target="_blank">Rogue.Win32.WindowsRiskMinimizer</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/27/windows-no-risk-agent-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows No-Risk Agent Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-no-risk-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows No-Risk Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/15/windows-risk-minimizer-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Managing System Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/14/windows-managing-system-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/14/windows-managing-system-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 14 Mar 2012 13:47:50 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Managing System]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3023</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Managing System. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsManagingSystem. Windows Managing System is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Managing System</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsManagingSystem" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsManagingSystem" target="_blank"><strong>Rogue.Win32.WindowsManagingSystem</strong></a><strong>.</strong></p>
<p><strong></strong><strong>Windows Managing System</strong> <strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Managing System.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Managing System.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsManagingSystem_1.png"><img class="alignnone size-medium wp-image-3024" title="Rogue.Win32.WindowsManagingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsManagingSystem_1-400x234.png" alt="Rogue.Win32.WindowsManagingSystem" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsManagingSystem_2.png"><img class="alignnone size-medium wp-image-3025" title="Rogue.Win32.WindowsManagingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsManagingSystem_2-400x293.png" alt="Rogue.Win32.WindowsManagingSystem" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsManagingSystem_3.png"><img class="alignnone size-medium wp-image-3026" title="Rogue.Win32.WindowsManagingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsManagingSystem_3-400x293.png" alt="Rogue.Win32.WindowsManagingSystem" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsManagingSystem_4.png"><img class="alignnone size-medium wp-image-3027" title="Rogue.Win32.WindowsManagingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsManagingSystem_4-400x238.png" alt="Rogue.Win32.WindowsManagingSystem" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsManagingSystem_5.png"><img class="alignnone size-medium wp-image-3028" title="Rogue.Win32.WindowsManagingSystem" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsManagingSystem_5-400x253.png" alt="Rogue.Win32.WindowsManagingSystem" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Managing System  </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsManagingSystem" target="_blank">Rogue.Win32.WindowsManagingSystem</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-trojans-inspector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Trojans Inspector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/windows-warding-system-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Warding System Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/14/windows-managing-system-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Tools Patch Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/13/windows-tools-patch-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/13/windows-tools-patch-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 13 Mar 2012 16:10:41 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Tools Patch]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3013</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Tools Patch. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsToolsPatch. Windows Tools Patch is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Tools Patch</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsToolsPatch" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsToolsPatch" target="_blank"><strong>Rogue.Win32.WindowsToolsPatch</strong></a><strong>.</strong></p>
<p><strong></strong><strong>Windows Tools Patch</strong> <strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Tools Patch.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Tools Patch.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsToolsPatch_1.png"><img class="alignnone size-medium wp-image-3014" title="Rogue.Win32.WindowsToolsPatch" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsToolsPatch_1-400x234.png" alt="Rogue.Win32.WindowsToolsPatch" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsToolsPatch_2.png"><img class="alignnone size-medium wp-image-3015" title="Rogue.Win32.WindowsToolsPatch" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsToolsPatch_2-400x293.png" alt="Rogue.Win32.WindowsToolsPatch" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsToolsPatch_3.png"><img class="alignnone size-medium wp-image-3016" title="Rogue.Win32.WindowsToolsPatch" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsToolsPatch_3-400x293.png" alt="Rogue.Win32.WindowsToolsPatch" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsToolsPatch_4.png"><img class="alignnone size-medium wp-image-3017" title="Rogue.Win32.WindowsToolsPatch" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsToolsPatch_4-400x238.png" alt="Rogue.Win32.WindowsToolsPatch" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsToolsPatch_5.png"><img class="alignnone size-medium wp-image-3018" title="Rogue.Win32.WindowsToolsPatch" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsToolsPatch_5-400x253.png" alt="Rogue.Win32.WindowsToolsPatch" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Tools Patch  </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsToolsPatch" target="_blank">Rogue.Win32.WindowsToolsPatch</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/04/17/windows-antivirus-patch-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Antivirus Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/windows-advanced-user-patch-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Advanced User Patch Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/09/windows-cleaning-tools-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Cleaning Tools Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/13/windows-tools-patch-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Antimalware PC Safety Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/08/antimalware-pc-safety-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/08/antimalware-pc-safety-rogue-removal-instructions/#comments</comments>
		<pubDate>Thu, 08 Mar 2012 08:10:24 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Antimalware PC Safety]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=3005</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Antimalware PC Safety. Emsisoft Anti-Malware detects this malware as Rogue.Win32.AntimalwarePCSafety. Antimalware PC Safety is a rogue scanner application, another variant of Best Virus Protection, Home Malware Cleaner, SmartAntiMalwareProtection, Antivirus Smart Protection, Malware Protection Center and Internet Security Guard. A rogue application tries to trick [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong><strong>Antimalware PC Safety</strong></strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.AntimalwarePCSafety" href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntimalwarePCSafety" target="_blank"><strong>Rogue.Win32.AntimalwarePCSafety</strong></a><strong>.</strong></p>
<p><strong>Antimalware PC Safety </strong><strong></strong>is a rogue scanner application, another variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BestVirusProtection"><strong>Best Virus Protection</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HomeMalwareCleaner"><strong>Home Malware Cleaner</strong></a>, <a title="Rogue.Win32.SmartAntiMalwareProtection" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartAntiMalwareProtection" target="_blank"><strong>SmartAntiMalwareProtection</strong></a><strong></strong>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirusSmartProtection"><strong>Antivirus Smart Protection</strong></a>, <a title="Malware Protection Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.MalwareProtectionCenter"><strong>Malware Protection Center</strong></a> and <a title="Rogue.Win32.InternetSecurityGuard" href="http://www.emsisoft.com/en/malware/?Adware.Win32.InternetSecurityGuard" target="_blank"><strong>Internet Security Guard</strong></a>. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\4f893a\</li>
<li>%AllUsersProfile%\Application Data\4f893a\873.mof</li>
<li>%AllUsersProfile%\Application Data\4f893a\AP4f8_8010.exe</li>
<li>%AllUsersProfile%\Application Data\4f893a\APCS.ico</li>
<li>%AllUsersProfile%\Application Data\4f893a\BackUp\</li>
<li>%AllUsersProfile%\Application Data\4f893a\Quarantine Items\</li>
<li>%AllUsersProfile%\Application Data\APGRBYPRCS\</li>
<li>%AllUsersProfile%\Application Data\APGRBYPRCS\APLHODBCS.cfg</li>
<li>%AppData%\Antimalware PC Safety\</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\Antimalware PC Safety.lnk</li>
<li>%UserProfile%\Desktop\Antimalware PC Safety.lnk</li>
<li>%Temp%\scandsk211d_8010.exe</li>
<li>%Temp%\del.bat</li>
<li>%UserProfile%\Start Menu\Antimalware PC Safety.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Antimalware PC Safety.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\<br />
URL = http://findgala.com/?&amp;uid=8074&amp;q={searchTerms}</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\3</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\<br />
ltTST = 91540000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures = no<br />
RunInvalidSignatures = 01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\SearchScopes\<br />
URL = http://findgala.com/?&amp;uid=8074&amp;q={searchTerms}</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Policies\Explorer\<br />
DisallowRun = 01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\<br />
0 = msseces.exe<br />
1 = MSASCui.exe<br />
2 = ekrn.exe<br />
3 = egui.exe<br />
4 = avgnt.exe<br />
5 = avcenter.exe<br />
6 = avscan.exe<br />
7 = avgfrw.exe<br />
8 = avgui.exe<br />
9 = avgtray.exe<br />
10 = avgscanx.exe<br />
11 = avgcfgex.exe<br />
12 = avgemc.exe<br />
13 = avgchsvx.exe<br />
14 = avgcmgr.exe<br />
15 = avgwdsvc.exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\<br />
BVP = “%AllUsersProfile%\Application Data\4f893a\AP4f8_8010.exe” /s<br />
Best Virus Protection = “%AllUsersProfile%\Application Data\4f893a\AP4f8_8010.exe” /s /d</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\RunOnce\<br />
BVP = “%Temp%\scandsk211d_8010.exe” /cs:0</li>
</ul>
<ul>
<li>HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\<br />
URL = http://findgala.com/?&amp;uid=8074&amp;q={searchTerms}</li>
</ul>
<ul>
<li>HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes\<br />
URL = http://findgala.com/?&amp;uid=8074&amp;q={searchTerms}</li>
</ul>
<ul>
<li>HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Internet Explorer\SearchScopes\<br />
URL = http://findgala.com/?&amp;uid=8074&amp;q={searchTerms}</li>
</ul>
<ul>
<li>HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes\<br />
URL = http://findgala.com/?&amp;uid=8074&amp;q={searchTerms}</li>
</ul>
<ul>
<li>HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Internet Explorer\SearchScopes\<br />
URL = http://findgala.com/?&amp;uid=8074&amp;q={searchTerms}</li>
</ul>
<ul>
<li> HKEY_LOCAL_MACHINE\Software\Classes\AP4f8_8010.DocHostUIHandler<br />
(Default)  = Implements DocHostUIHandler<br />
Clsid  = {3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
</ul>
<ul>
<li> HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}<br />
(Default)  = Implements DocHostUIHandler<br />
LocalServer32  = %AllUsersProfile%\Application Data\4f893a\AP4f8_8010.exe<br />
ProgID  = AP4f8_8010.DocHostUIHandler</li>
</ul>
<ul>
<li> HKEY_LOCAL_MACHINE\Software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.AntimalwarePCSafety_1.png"><img class="alignnone size-medium wp-image-3006" title="Rogue.Win32.AntimalwarePCSafety" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.AntimalwarePCSafety_1-400x201.png" alt="Rogue.Win32.AntimalwarePCSafety" width="400" height="201" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.AntimalwarePCSafety_2.png"><img class="alignnone size-medium wp-image-3007" title="Rogue.Win32.AntimalwarePCSafety" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.AntimalwarePCSafety_2-400x292.png" alt="Rogue.Win32.AntimalwarePCSafety" width="400" height="292" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.AntimalwarePCSafety_3.png"><img class="alignnone size-medium wp-image-3008" title="Rogue.Win32.AntimalwarePCSafety" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.AntimalwarePCSafety_3-400x292.png" alt="Rogue.Win32.AntimalwarePCSafety" width="400" height="292" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.AntimalwarePCSafety_4.png"><img class="alignnone size-medium wp-image-3009" title="Rogue.Win32.AntimalwarePCSafety" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.AntimalwarePCSafety_4-400x290.png" alt="Rogue.Win32.AntimalwarePCSafety" width="400" height="290" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><strong></strong><span style="color: #ff0000;"><strong>U2FD-S2LA-H4KA-UEPB</strong></span></pre>
<p><strong>How to remove the infection of Antimalware PC Safety </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntimalwarePCSafety" target="_blank">Rogue.Win32.AntimalwarePCSafety</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/08/best-virus-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Best Virus Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/total-anti-malware-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Total Anti Malware Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/best-antivirus-software-rogue-removal-instructions/" rel="bookmark" class="crp_title">Best Antivirus Software Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/02/21/home-malware-cleaner-rogue-removal-instructions/" rel="bookmark" class="crp_title">Home Malware Cleaner Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/08/antimalware-pc-safety-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Best Virus Protection Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/08/best-virus-protection-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/08/best-virus-protection-rogue-removal-instructions/#comments</comments>
		<pubDate>Thu, 08 Mar 2012 07:09:39 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Best Virus Protection]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2996</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Best Virus Protection. Emsisoft Anti-Malware detects this malware as Rogue.Win32.BestVirusProtection. Best Virus Protection is a rogue scanner application, another variant of Home Malware Cleaner, SmartAntiMalwareProtection, Antivirus Smart Protection, Malware Protection Center and Internet Security Guard. A rogue application tries to trick you by displaying [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong>Best Virus Protection</strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.BestVirusProtection" href="http://www.emsisoft.com/en/malware/?Adware.Win32.BestVirusProtection" target="_blank"><strong>Rogue.Win32.BestVirusProtection</strong></a><strong>.</strong></p>
<p><strong>Best Virus Protection </strong><strong></strong>is a rogue scanner application, another variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HomeMalwareCleaner"><strong>Home Malware Cleaner</strong></a>, <a title="Rogue.Win32.SmartAntiMalwareProtection" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartAntiMalwareProtection" target="_blank"><strong>SmartAntiMalwareProtection</strong></a><strong></strong>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirusSmartProtection"><strong>Antivirus Smart Protection</strong></a>, <a title="Malware Protection Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.MalwareProtectionCenter"><strong>Malware Protection Center</strong></a> and <a title="Rogue.Win32.InternetSecurityGuard" href="http://www.emsisoft.com/en/malware/?Adware.Win32.InternetSecurityGuard" target="_blank"><strong>Internet Security Guard</strong></a>. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\4f893a\</li>
<li>%AllUsersProfile%\Application Data\4f893a\BV4f8_8074.exe</li>
<li>%AllUsersProfile%\Application Data\4f893a\BVP.ico</li>
<li>%AllUsersProfile%\Application Data\4f893a\BackUp\</li>
<li>%AllUsersProfile%\Application Data\4f893a\BVPSys\</li>
<li>%AllUsersProfile%\Application Data\4f893a\Quarantine Items\</li>
<li>%AllUsersProfile%\Application Data\4f893a\7467.mof</li>
<li>%AllUsersProfile%\Application Data\BVJNZDSZHP\</li>
<li>%AllUsersProfile%\Application Data\BVJNZDSZHP\BVSUKYOP.cfg</li>
<li>%AppData%\Best Virus Protection\</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\Best Virus Protection.lnk</li>
<li>%UserProfile%\Desktop\Best Virus Protection.lnk</li>
<li>%Temp%\scandsk1007d_8074.exe</li>
<li>%Temp%\del.bat</li>
<li>%UserProfile%\Recent\exec.exe</li>
<li>%UserProfile%\Recent\hymt.exe</li>
<li>%UserProfile%\Start Menu\Best Virus Protection.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Best Virus Protection.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\<br />
URL = http://findgala.com/?&amp;uid=8074&amp;q={searchTerms}</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\3</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\<br />
ltTST = 91540000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures = no<br />
RunInvalidSignatures = 01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\SearchScopes\<br />
URL = http://findgala.com/?&amp;uid=8074&amp;q={searchTerms}</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Policies\Explorer\<br />
DisallowRun = 01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\<br />
0 = msseces.exe<br />
1 = MSASCui.exe<br />
2 = ekrn.exe<br />
3 = egui.exe<br />
4 = avgnt.exe<br />
5 = avcenter.exe<br />
6 = avscan.exe<br />
7 = avgfrw.exe<br />
8 = avgui.exe<br />
9 = avgtray.exe<br />
10 = avgscanx.exe<br />
11 = avgcfgex.exe<br />
12 = avgemc.exe<br />
13 = avgchsvx.exe<br />
14 = avgcmgr.exe<br />
15 = avgwdsvc.exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\<br />
BVP = &#8220;%AllUsersProfile%\Application Data\4f893a\BV4f8_8074.exe&#8221; /s<br />
Best Virus Protection = &#8220;%AllUsersProfile%\Application Data\4f893a\BV4f8_8074.exe&#8221; /s /d</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\RunOnce\<br />
BVP = &#8220;%Temp%\scandsk1007d_8074.exe&#8221; /cs:0</li>
</ul>
<ul>
<li>HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\<br />
URL = http://findgala.com/?&amp;uid=8074&amp;q={searchTerms}</li>
</ul>
<ul>
<li>HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes\<br />
URL = http://findgala.com/?&amp;uid=8074&amp;q={searchTerms}</li>
</ul>
<ul>
<li>HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Internet Explorer\SearchScopes\<br />
URL = http://findgala.com/?&amp;uid=8074&amp;q={searchTerms}</li>
</ul>
<ul>
<li>HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes\<br />
URL = http://findgala.com/?&amp;uid=8074&amp;q={searchTerms}</li>
</ul>
<ul>
<li>HKEY_USERS\S-1-5-20_Classes\Software\Microsoft\Internet Explorer\SearchScopes\<br />
URL = http://findgala.com/?&amp;uid=8074&amp;q={searchTerms}</li>
</ul>
<ul>
<li> HKEY_LOCAL_MACHINE\Software\Classes\BV4f8_8074.DocHostUIHandler<br />
(Default)  = Implements DocHostUIHandler<br />
Clsid  = {3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
</ul>
<ul>
<li> HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}<br />
(Default)  = Implements DocHostUIHandler<br />
LocalServer32  = %AllUsersProfile%\Application Data\4f893a\BV4f8_8074.exe<br />
ProgID  = BV4f8_8074.DocHostUIHandler</li>
</ul>
<ul>
<li> HKEY_LOCAL_MACHINE\Software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.BestVirusProtection_1.png"><img class="alignnone size-medium wp-image-2997" title="Rogue.Win32.BestVirusProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.BestVirusProtection_1-400x292.png" alt="Rogue.Win32.BestVirusProtection" width="400" height="292" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.BestVirusProtection_2.png"><img class="alignnone size-medium wp-image-2998" title="Rogue.Win32.BestVirusProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.BestVirusProtection_2-400x292.png" alt="Rogue.Win32.BestVirusProtection" width="400" height="292" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.BestVirusProtection_3.png"><img class="alignnone size-medium wp-image-2999" title="Rogue.Win32.BestVirusProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.BestVirusProtection_3-400x292.png" alt="Rogue.Win32.BestVirusProtection" width="400" height="292" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.BestVirusProtection_4.png"><img class="alignnone size-medium wp-image-3000" title="Rogue.Win32.BestVirusProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.BestVirusProtection_4-400x197.png" alt="Rogue.Win32.BestVirusProtection" width="400" height="197" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><strong></strong><span style="color: #ff0000;"><strong>U2FD-S2LA-H4KA-UEPB</strong></span></pre>
<p><strong>How to remove the infection of Best Virus Protection </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.BestVirusProtection" target="_blank">Rogue.Win32.BestVirusProtection</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/08/antimalware-pc-safety-rogue-removal-instructions/" rel="bookmark" class="crp_title">Antimalware PC Safety Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/total-anti-malware-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Total Anti Malware Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Smart Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/05/07/best-antivirus-software-rogue-removal-instructions/" rel="bookmark" class="crp_title">Best Antivirus Software Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/08/best-virus-protection-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Personal Doctor Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/08/windows-personal-doctor-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/08/windows-personal-doctor-rogue-removal-instructions/#comments</comments>
		<pubDate>Thu, 08 Mar 2012 05:41:15 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Personal Doctor]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2987</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Personal Doctor. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsPersonalDoctor. Windows Personal Doctor is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Personal Doctor</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsPersonalDoctor" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPersonalDoctor" target="_blank"><strong>Rogue.Win32.WindowsPersonalDoctor</strong></a><strong>.</strong></p>
<p><strong></strong><strong>Windows Personal Doctor</strong> <strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%AppData%\NPSWF32.dll</li>
<li>%AppData%\npswf32.tmp</li>
<li>%UserProfile%\Desktop\Windows Personal Doctor.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Personal Doctor.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsPersonalDoctor_1.png"><img class="alignnone size-medium wp-image-2988" title="Rogue.Win32.WindowsPersonalDoctor" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsPersonalDoctor_1-400x234.png" alt="Rogue.Win32.WindowsPersonalDoctor" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsPersonalDoctor_2.png"><img class="alignnone size-medium wp-image-2989" title="Rogue.Win32.WindowsPersonalDoctor" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsPersonalDoctor_2-400x293.png" alt="Rogue.Win32.WindowsPersonalDoctor" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsPersonalDoctor_3.png"><img class="alignnone size-medium wp-image-2990" title="Rogue.Win32.WindowsPersonalDoctor" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsPersonalDoctor_3-400x293.png" alt="Rogue.Win32.WindowsPersonalDoctor" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsPersonalDoctor_4.png"><img class="alignnone size-medium wp-image-2991" title="Rogue.Win32.WindowsPersonalDoctor" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsPersonalDoctor_4-400x238.png" alt="Rogue.Win32.WindowsPersonalDoctor" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsPersonalDoctor_5.png"><img class="alignnone size-medium wp-image-2992" title="Rogue.Win32.WindowsPersonalDoctor" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsPersonalDoctor_5-400x253.png" alt="Rogue.Win32.WindowsPersonalDoctor" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Personal Doctor  </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPersonalDoctor" target="_blank">Rogue.Win32.WindowsPersonalDoctor</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/07/windows-personal-detective-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Personal Detective Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-trojans-inspector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Trojans Inspector Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/08/windows-personal-doctor-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Personal Detective Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/07/windows-personal-detective-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/07/windows-personal-detective-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 07 Mar 2012 18:40:40 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Personal Detective]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2979</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Personal Detective. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsPersonalDetective. Windows Personal Detective is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Personal Detective</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsPersonalDetective" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPersonalDetective" target="_blank"><strong>Rogue.Win32.WindowsPersonalDetective</strong></a><strong>.</strong></p>
<p><strong></strong><strong>Windows Personal Detective</strong> <strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-[random].exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Personal Detective.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Personal Detective.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-[random].exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsPersonalDetective_1.png"><img class="alignnone size-medium wp-image-2980" title="Rogue.Win32.WindowsPersonalDetective" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsPersonalDetective_1-400x234.png" alt="Rogue.Win32.WindowsPersonalDetective" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsPersonalDetective_2.png"><img class="alignnone size-medium wp-image-2981" title="Rogue.Win32.WindowsPersonalDetective" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsPersonalDetective_2-400x293.png" alt="Rogue.Win32.WindowsPersonalDetective" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsPersonalDetective_3.png"><img class="alignnone size-medium wp-image-2982" title="Rogue.Win32.WindowsPersonalDetective" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsPersonalDetective_3-400x293.png" alt="Rogue.Win32.WindowsPersonalDetective" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsPersonalDetective_4.png"><img class="alignnone size-medium wp-image-2983" title="Rogue.Win32.WindowsPersonalDetective" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsPersonalDetective_4-400x238.png" alt="Rogue.Win32.WindowsPersonalDetective" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsPersonalDetective_5.png"><img class="alignnone size-medium wp-image-2984" title="Rogue.Win32.WindowsPersonalDetective" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsPersonalDetective_5-400x253.png" alt="Rogue.Win32.WindowsPersonalDetective" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Personal Detective  </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPersonalDetective" target="_blank">Rogue.Win32.WindowsPersonalDetective</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/08/windows-personal-doctor-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Personal Doctor Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-trojans-inspector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Trojans Inspector Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/07/windows-personal-detective-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Malware Sleuth Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 06 Mar 2012 12:10:27 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Malware Sleuth]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2971</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Malware Sleuth. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsMalwareSleuth. Windows  Malware Sleuth is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Malware Sleuth</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsMalwareSleuth" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMalwareSleuth" target="_blank"><strong>Rogue.Win32.WindowsMalwareSleuth</strong></a><strong>.</strong></p>
<p><strong>Windows  Malware Sleuth</strong> <strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-ogp.exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Malware Sleuth.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Malware Sleuth.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-ogp.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsMalwareSleuth_1.png"><img class="alignnone size-medium wp-image-2972" title="Rogue.Win32.WindowsMalwareSleuth" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsMalwareSleuth_1-400x234.png" alt="Rogue.Win32.WindowsMalwareSleuth" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsMalwareSleuth_2.png"><img class="alignnone size-medium wp-image-2973" title="Rogue.Win32.WindowsMalwareSleuth" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsMalwareSleuth_2-400x293.png" alt="Rogue.Win32.WindowsMalwareSleuth" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsMalwareSleuth_3.png"><img class="alignnone size-medium wp-image-2974" title="Rogue.Win32.WindowsMalwareSleuth" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsMalwareSleuth_3-400x293.png" alt="Rogue.Win32.WindowsMalwareSleuth" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsMalwareSleuth_4.png"><img class="alignnone size-medium wp-image-2975" title="Rogue.Win32.WindowsMalwareSleuth" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsMalwareSleuth_4-400x238.png" alt="Rogue.Win32.WindowsMalwareSleuth" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsMalwareSleuth_5.png"><img class="alignnone size-medium wp-image-2976" title="Rogue.Win32.WindowsMalwareSleuth" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsMalwareSleuth_5-400x253.png" alt="Rogue.Win32.WindowsMalwareSleuth" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Malware Sleuth  </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsMalwareSleuth" target="_blank">Rogue.Win32.WindowsMalwareSleuth</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-trojans-inspector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Trojans Inspector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/02/windows-attacks-defender-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Attacks Defender Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/02/windows-firewall-constructor-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Firewall Constructor Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Trojans Inspector Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/06/windows-trojans-inspector-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/06/windows-trojans-inspector-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 06 Mar 2012 12:05:01 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Trojans Inspector]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2963</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Trojans Inspector. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsTrojansInspector. Windows Trojans Inspector is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Trojans Inspector</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsTrojansInspector" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTrojansInspector" target="_blank"><strong>Rogue.Win32.WindowsTrojansInspector</strong></a><strong>.</strong></p>
<p><strong>Windows Trojans Inspector</strong> <strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-thg.exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Trojans Inspector.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Trojans Inspector.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-thg.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsTrojansInspector_1.png"><img class="alignnone size-medium wp-image-2964" title="Rogue.Win32.WindowsTrojansInspector" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsTrojansInspector_1-400x234.png" alt="Rogue.Win32.WindowsTrojansInspector" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsTrojansInspector_2.png"><img class="alignnone size-medium wp-image-2965" title="Rogue.Win32.WindowsTrojansInspector" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsTrojansInspector_2-400x293.png" alt="Rogue.Win32.WindowsTrojansInspector" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsTrojansInspector_3.png"><img class="alignnone size-medium wp-image-2966" title="Rogue.Win32.WindowsTrojansInspector" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsTrojansInspector_3-400x293.png" alt="Rogue.Win32.WindowsTrojansInspector" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsTrojansInspector_4.png"><img class="alignnone size-medium wp-image-2967" title="Rogue.Win32.WindowsTrojansInspector" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsTrojansInspector_4-400x238.png" alt="Rogue.Win32.WindowsTrojansInspector" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsTrojansInspector_5.png"><img class="alignnone size-medium wp-image-2968" title="Rogue.Win32.WindowsTrojansInspector" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsTrojansInspector_5-400x253.png" alt="Rogue.Win32.WindowsTrojansInspector" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Trojans Inspector  </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTrojansInspector" target="_blank">Rogue.Win32.WindowsTrojansInspector</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/02/windows-attacks-defender-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Attacks Defender Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/02/windows-firewall-constructor-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Firewall Constructor Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/06/windows-trojans-inspector-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Attacks Defender Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/02/windows-attacks-defender-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/02/windows-attacks-defender-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 02 Mar 2012 12:17:26 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Attacks Defender]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2954</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Attacks Defender. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsAttacksDefender. Windows Attacks Defender is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Attacks Defender</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsAttacksDefender" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAttacksDefender" target="_blank"><strong>Rogue.Win32.WindowsAttacksDefender</strong></a><strong>.</strong></p>
<p><strong>Windows Attacks </strong><strong>Defender</strong> <strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-jtj.exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Attacks Defender.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Attacks Defender.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-jtj.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAttacksDefender_1.png"><img class="alignnone size-medium wp-image-2955" title="Rogue.Win32.WindowsAttacksDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAttacksDefender_1-400x234.png" alt="Rogue.Win32.WindowsAttacksDefender" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAttacksDefender_2.png"><img class="alignnone size-medium wp-image-2956" title="Rogue.Win32.WindowsAttacksDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAttacksDefender_2-400x293.png" alt="Rogue.Win32.WindowsAttacksDefender" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAttacksDefender_3.png"><img class="alignnone size-medium wp-image-2957" title="Rogue.Win32.WindowsAttacksDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAttacksDefender_3-400x293.png" alt="Rogue.Win32.WindowsAttacksDefender" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAttacksDefender_4.png"><img class="alignnone size-medium wp-image-2958" title="Rogue.Win32.WindowsAttacksDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAttacksDefender_4-400x238.png" alt="Rogue.Win32.WindowsAttacksDefender" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAttacksDefender_5.png"><img class="alignnone size-medium wp-image-2959" title="Rogue.Win32.WindowsAttacksDefender" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAttacksDefender_5-400x253.png" alt="Rogue.Win32.WindowsAttacksDefender" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Attacks Defender  </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAttacksDefender" target="_blank">Rogue.Win32.WindowsAttacksDefender</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/02/windows-attacks-preventor-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Attacks Preventor Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-trojans-inspector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Trojans Inspector Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/02/windows-attacks-defender-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Attacks Preventor Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/02/windows-attacks-preventor-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/02/windows-attacks-preventor-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 02 Mar 2012 08:52:32 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Attacks Preventor]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2944</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Attacks Preventor. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsAttacksPreventor. Windows Attacks Preventor is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Attacks Preventor</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsAttacksPreventor" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAttacksPreventor" target="_blank"><strong>Rogue.Win32.WindowsAttacksPreventor</strong></a><strong>.</strong></p>
<p><strong>Windows Attacks Preventor </strong><strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-lcl.exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Attacks Preventor.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Attacks Preventor.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-lcl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAttacksPreventor_1.png"><img class="alignnone size-medium wp-image-2945" title="Rogue.Win32.WindowsAttacksPreventor" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAttacksPreventor_1-400x234.png" alt="Rogue.Win32.WindowsAttacksPreventor" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAttacksPreventor_2.png"><img class="alignnone size-medium wp-image-2946" title="Rogue.Win32.WindowsAttacksPreventor" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAttacksPreventor_2-400x293.png" alt="Rogue.Win32.WindowsAttacksPreventor" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAttacksPreventor_3.png"><img class="alignnone size-medium wp-image-2947" title="Rogue.Win32.WindowsAttacksPreventor" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAttacksPreventor_3-400x293.png" alt="Rogue.Win32.WindowsAttacksPreventor" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAttacksPreventor_4.png"><img class="alignnone size-medium wp-image-2948" title="Rogue.Win32.WindowsAttacksPreventor" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAttacksPreventor_4-400x238.png" alt="Rogue.Win32.WindowsAttacksPreventor" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAttacksPreventor_5.png"><img class="alignnone size-medium wp-image-2949" title="Rogue.Win32.WindowsAttacksPreventor" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsAttacksPreventor_5-400x253.png" alt="Rogue.Win32.WindowsAttacksPreventor" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Attacks Preventor </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsAttacksPreventor" target="_blank">Rogue.Win32.WindowsAttacksPreventor</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/02/windows-attacks-defender-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Attacks Defender Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-trojans-inspector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Trojans Inspector Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/02/windows-attacks-preventor-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Threats Destroyer Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/02/windows-threats-destroyer-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/02/windows-threats-destroyer-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 02 Mar 2012 08:36:41 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Threats Destroyer]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2935</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Threats Destroyer. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsThreatsDestroyer. Windows Threats Destroyer is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Threats Destroyer</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsThreatsDestroyer" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsDestroyer" target="_blank"><strong>Rogue.Win32.WindowsThreatsDestroyer</strong></a><strong>.</strong></p>
<p><strong>Windows Threats Destroyer </strong><strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-jcl.exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Threats Destroyer.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Threats Destroyer.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-jcl.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries…</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsThreatDestroyer_1.png"><img class="alignnone size-medium wp-image-2936" title="Rogue.Win32.WindowsThreatDestroyer" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsThreatDestroyer_1-400x234.png" alt="Rogue.Win32.WindowsThreatDestroyer" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsThreatDestroyer_2.png"><img class="alignnone size-medium wp-image-2937" title="Rogue.Win32.WindowsThreatDestroyer" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsThreatDestroyer_2-400x293.png" alt="Rogue.Win32.WindowsThreatDestroyer" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsThreatDestroyer_3.png"><img class="alignnone size-medium wp-image-2938" title="Rogue.Win32.WindowsThreatDestroyer" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsThreatDestroyer_3-400x293.png" alt="Rogue.Win32.WindowsThreatDestroyer" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsThreatDestroyer_4.png"><img class="alignnone size-medium wp-image-2939" title="Rogue.Win32.WindowsThreatDestroyer" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsThreatDestroyer_4-400x238.png" alt="Rogue.Win32.WindowsThreatDestroyer" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsThreatDestroyer_5.png"><img class="alignnone size-medium wp-image-2940" title="Rogue.Win32.WindowsThreatDestroyer" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsThreatDestroyer_5-400x253.png" alt="Rogue.Win32.WindowsThreatDestroyer" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Threats Destroyer </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsThreatsDestroyer" target="_blank">Rogue.Win32.WindowsThreatsDestroyer</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-trojans-inspector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Trojans Inspector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/02/windows-attacks-defender-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Attacks Defender Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/02/windows-threats-destroyer-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Firewall Constructor Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/03/02/windows-firewall-constructor-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/03/02/windows-firewall-constructor-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 02 Mar 2012 08:15:50 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Firewall Constructor]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2926</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Firewall Constructor. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsFirewallConstructor. Windows Firewall Constructor is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Firewall Constructor</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsFirewallConstructor" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallConstructor" target="_blank"><strong>Rogue.Win32.WindowsFirewallConstructor</strong></a><strong>.</strong></p>
<p><strong>Windows Firewall Constructor </strong><strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-cyk.exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Firewall Constructor.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Firewall Constructor.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-cyk.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>many similar entries&#8230;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsFirewallConstructor_1.png"><img class="alignnone size-medium wp-image-2927" title="Rogue.Win32.WindowsFirewallConstructor" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsFirewallConstructor_1-400x234.png" alt="Rogue.Win32.WindowsFirewallConstructor" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsFirewallConstructor_2.png"><img class="alignnone size-medium wp-image-2928" title="Rogue.Win32.WindowsFirewallConstructor" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsFirewallConstructor_2-400x293.png" alt="Rogue.Win32.WindowsFirewallConstructor" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsFirewallConstructor_3.png"><img class="alignnone size-medium wp-image-2929" title="Rogue.Win32.WindowsFirewallConstructor" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsFirewallConstructor_3-400x293.png" alt="Rogue.Win32.WindowsFirewallConstructor" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsFirewallConstructor_4.png"><img class="alignnone size-medium wp-image-2930" title="Rogue.Win32.WindowsFirewallConstructor" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsFirewallConstructor_4-400x238.png" alt="Rogue.Win32.WindowsFirewallConstructor" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsFirewallConstructor_5.png"><img class="alignnone size-medium wp-image-2931" title="Rogue.Win32.WindowsFirewallConstructor" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/03/Rogue.Win32.WindowsFirewallConstructor_5-400x253.png" alt="Rogue.Win32.WindowsFirewallConstructor" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Firewall Constructor </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFirewallConstructor" target="_blank">Rogue.Win32.WindowsFirewallConstructor</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-trojans-inspector-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Trojans Inspector Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/02/windows-attacks-defender-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Attacks Defender Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/03/02/windows-firewall-constructor-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Smart Fortress 2012 Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/02/29/smart-fortress-2012-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/02/29/smart-fortress-2012-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 29 Feb 2012 10:15:11 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Smart Fortress 2012]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2919</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Smart Fortress 2012. Emsisoft Anti-Malware detects this malware as Rogue.Win32.SmartFortress2012. Smart Fortress 2012 is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Smart Fortress 2012</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.SmartFortress2012" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartFortress2012" target="_blank"><strong>Rogue.Win32.SmartFortress2012</strong></a><strong>.</strong></p>
<p><strong>Smart Fortress 2012 </strong><strong></strong>is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\</li>
<li>%AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\B7E85B320179A6C600266C1CD151FC4E</li>
<li>%AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\B7E85B320179A6C600266C1CD151FC4E.exe</li>
<li>%UserProfile%\Desktop\Smart Fortress 2012.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Smart Fortress 2012\</li>
<li>%UserProfile%\Start Menu\Programs\Smart Fortress 2012\Smart Fortress 2012.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Classes\.exe\<br />
(Default) = B7E85</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Classes\%s<br />
(Default) = B7E85</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Classes\B7E85\<br />
(Default) = Application<br />
Content Type = application/x-msdownload</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Classes\B7E85\DefaultIcon<br />
(Default) = %1</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Classes\B7E85\shell\open\command\<br />
(Default) = %AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\B7E85B320179A6C600266C1CD151FC4E.exe<br />
IsolatedCommand = &#8220;%1&#8243; %*</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Classes\B7E85\shell\runas\command\<br />
(Default) = &#8220;%1&#8243; %*<br />
IsolatedCommand = &#8220;%1&#8243; %*</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Classes\B7E85\shell\start\command\<br />
(Default) = &#8220;%1&#8243; %*<br />
IsolatedCommand = &#8220;%1&#8243; %*</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\RunOnce\<br />
B7E85B320179A6C600266C1CD151FC4E = %AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\B7E85B320179A6C600266C1CD151FC4E.exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Uninstall\Smart Fortress 2012\<br />
DisplayName = Smart Fortress 2012<br />
ShortcutPath = “%AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\B7E85B320179A6C600266C1CD151FC4E.exe” -u<br />
UninstallString = “%AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\B7E85B320179A6C600266C1CD151FC4E.exe” -u<br />
DisplayIcon = %AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\B7E85B320179A6C600266C1CD151FC4E.exe,0</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SmartFortress2012_1.png"><img class="alignnone size-medium wp-image-2920" title="Rogue.Win32.SmartFortress2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SmartFortress2012_1-400x298.png" alt="Rogue.Win32.SmartFortress2012" width="400" height="298" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SmartFortress2012_2.png"><img class="alignnone size-medium wp-image-2921" title="Rogue.Win32.SmartFortress2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SmartFortress2012_2-400x342.png" alt="Rogue.Win32.SmartFortress2012" width="400" height="342" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SmartFortress2012_3.png"><img class="alignnone size-full wp-image-2922" title="Rogue.Win32.SmartFortress2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SmartFortress2012_3.png" alt="Rogue.Win32.SmartFortress2012" width="400" height="380" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SmartFortress2012_4.png"><img class="alignnone size-medium wp-image-2923" title="Rogue.Win32.SmartFortress2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SmartFortress2012_4-400x210.png" alt="Rogue.Win32.SmartFortress2012" width="400" height="210" /></a></p>
<p>To register this rogue application, you try the following serial number:</p>
<pre><strong></strong><span style="color: #ff0000;"><strong>AA39754E-715219CE</strong></span></pre>
<p><strong>How to remove the infection of Smart Fortress 2012 </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartFortress2012" target="_blank">Rogue.Win32.SmartFortress2012</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/23/smart-protection-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Smart Protection 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/smart-hdd-rogue-removal-instructions/" rel="bookmark" class="crp_title">SMART HDD Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/29/xp-antivirus-2012-multifakeav-rogue-removal-instructions/" rel="bookmark" class="crp_title">XP Antivirus 2012 (MultiFakeAV) Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/23/internet-security-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/03/security-sphere-2012-removal-instructions/" rel="bookmark" class="crp_title">Security Sphere 2012 Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/02/29/smart-fortress-2012-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Stability Guard Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/02/29/windows-stability-guard-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/02/29/windows-stability-guard-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 29 Feb 2012 09:49:54 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Stability Guard]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2911</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Stability Guard. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsStabilityGuard. Windows Stability Guard is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Stability Guard</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsStabilityGuard" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityGuard" target="_blank"><strong>Rogue.Win32.WindowsStabilityGuard</strong></a><strong>.</strong></p>
<p><strong>Windows Stability Guard </strong><strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-ode.exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Stability Guard.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Stability Guard.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AluSchedulerSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\amon9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\anti-trojan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirus.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ants.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\apimonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aplica32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\apvxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\arr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashAvast.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashBug.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashChest.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashCnsnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashLogV.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashMaiSv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashPopWz.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashQuick.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashServ.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSimp2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSimpl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSkPcc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSkPck.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashUpd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashWebSv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswChLic.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswRegSvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswRunDll.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswUpdSv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atcon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atro55en.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atupdater.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\au.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\auto-protect.nav80try.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\autodown.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\autotrace.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avadmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avcenter.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avciman.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconfig.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconsol.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ave32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgchk.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcsrvx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgdumpx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgemc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgiproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnsx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrsx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgscanx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgserv9.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgsrmax.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgtray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgwdsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkpop.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkservice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkwctl9.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avltmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avmailc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avmcdlg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avnotify.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpcc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpdos32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avptc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avsched32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avsynmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avupgsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVWEBGRD.EXE\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwin95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwinnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwsc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupsrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxmonitor9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxmonitornt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxquar.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\b.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\backweb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bargains.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvcl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvwiz.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDInProcPatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdmcon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDMsnScan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDSurvey.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bd_professional.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\beagle.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\belt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bidef.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bidserver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bipcp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bipcpevalsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bisp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blackd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blackice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blink.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blss.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bootconf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bootwarn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\borg2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brasil.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bs120.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bspatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bundle.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bvt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\c.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cavscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccevtmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccpxysvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccSvcHst.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cdp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfgwiz.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfiadmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfiaudit.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfinet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfinet32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfpconfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfplogvw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfpupdat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\claw95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\claw95cf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\clean.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleaner.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleaner3.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleanIELow.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleanpc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\click.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmdagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmesys.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmgrdian.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmon016.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\connectionmonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\control\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpf9x206.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpfnt206.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\crashrep.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssconfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssupdat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssurf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cwnb181.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cwntdwmo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\d.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\datemanager.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dcomx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\defalert.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\defscangui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\defwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\deloeminfs.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\deputy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dllcache.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dllreg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\doors.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpfsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpps2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\driverctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\drwatson.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\drweb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\drwebupw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dssagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dvp95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dvp95_0.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ecengine.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\efpeadm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\emsw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\esafe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\escanhnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\escanv95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\espwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ethereal.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\etrustcipe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\evpn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\exantivirus-cnet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\exe.avxw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\expert.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\explore.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-agnt95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-prot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-prot95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-stopw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fact.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fameh32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fast.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fch32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fih32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\findviru.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\firewall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fixcfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fixfp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fnrb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fp-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fp-win_trial.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fprot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frmwrk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsaa.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav530stbyb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav530wtbyb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsgk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsm32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsma32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsmb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gator.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbmenu.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbpoll.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\generics.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gmt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\guard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\guarddog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\guardgui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hacktracersetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hbinst.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hbsrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\History.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\homeav2010.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hotactio.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hotpatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\htlog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\htpatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hwpe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hxdl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hxiul.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamstats.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ibmasn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ibmavsp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icload95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icloadnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icsupp95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icsuppnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Identity.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\idle.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iedll.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iedriver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\IEShow.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iface.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ifw2000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\inetlnfo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\infus.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\infwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init32.exe \<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[1].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[2].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[3].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[4].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[5].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\intdel.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\intren.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iomon98.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\istsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\jammer.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\jdbgmrg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\jedi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\JsRcGen.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavlite40eng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavpers40eng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavpf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kazza.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\keenvalue.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-pf-213-en-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-wrl-421-en-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-wrp-421-en-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\killprocesssetup161.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldnetmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldpro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldpromenu.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\licmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lnetinfo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\loader.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\localnet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lockdown.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lockdown2000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lookout.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lordpe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luau.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lucomserver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luinit.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luspt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MalwareRemoval.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mapisvc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcmnhdlr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcmscsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcnasvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\McSACore.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcshell.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcshield.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcsysmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mctool.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcvsrte.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcvsshld.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\md.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfw2en.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfweng3.02d30.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgavrtcl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgavrte.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mghtml.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\minilog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmod.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\monitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\moolive.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpfagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpfservice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MPFSrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpftray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mrflux.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mrt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msa.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msbb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msblast.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscache.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msccn32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscman.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msdm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msdos.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msiexec16.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mslaugh.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmgt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmsgri32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mssmmc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mssys.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msvxd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mu0311ad.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\n32scanw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navap.navapsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navapsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navapw32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navdx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navlu32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navstub.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navw32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navwnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nc2000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ncinst4.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ndd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\neomonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\neowatchlog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netarmor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netinfo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netscanpro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netspyhunter-1.2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netutils.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nisserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nisum.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\normist.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\norton_internet_secu_3.0_407.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\notstart.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npf40_tw_98_nt_me_2k.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npfmessenger.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nprotect.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npscheck.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npssvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nsched32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nssys32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nstask32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nsupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntrtscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntvdm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntxconfig.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nupgrade.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvarch16.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvc95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvsvc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwinst4.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwservice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwtool16.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAcat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAhlp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAReg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\oasrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\oaui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\oaview.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ODSW.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ollydbg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\onsrvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\optimize.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ostronet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\otfix.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpostinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpostproinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ozn695m5.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\padmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\panixk.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\patch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavcl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PavFnSvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavprsrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavsched.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavsrv51.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pccwin98.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcfwallicon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcip10117_0.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsAuxs.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsGui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PC_Antispyware2010.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfndr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PerAvir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\periscope.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\persfw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\perswf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pf2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pfwadmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pgmonitr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pingscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pop3trap.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\poproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\popscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\portdetective.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\portmonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ppinupdt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pptbc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ppvstop.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\prizesurfer.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\prmt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\prmvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\procdump.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\processmonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexplorerv1.0.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\programauditor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\proport.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protector.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANCU.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANHost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANToManager.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PsCtrls.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PsImSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PskSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pspf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSUNMain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\purge.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qconsole.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qh.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qserver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quick Heal.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\QuickHealCleaner.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rapapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav7.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav7win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav8win32eng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rcsync.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\realmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\reged.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe\<br />
Debugger = %AppData%\Inspector-ode.exe reg</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedt32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rescue.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rescue32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rrguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rscdwld.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rshell.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rtvscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rtvscn95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rulaunch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeweb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sahagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Save.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveArmor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveDefense.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveKeep.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\savenow.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sbserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scam32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scanpm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scrscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secure Veteran.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\secureveteran.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Security Center.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SecurityFighter.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\securitysoldier.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\serv95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\setloadorder.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\setupvameeval.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup_flowprotector_us.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sgssfw32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sh.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\shellspyinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\shield.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\shn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\showbehind.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\signcheck.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smart.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartprotector.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smrtdefp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sms.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smss32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\snetcfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\soap.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sofi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftSafeness.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sperm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sphinx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoler.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolcv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolsv32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spywarexpguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spyxx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\srexe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\srng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ss3edit.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssgrate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssg_4104.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\st2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\start.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\stcloader.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\supftrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\support.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\supporter5.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchostc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchosts.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svshost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweep95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweepnet.sweepsrv.sys.swnetsup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\symproxysvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\symtray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\system.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\system32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sysupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe\<br />
Debugger = %AppData%\Inspector-ode.exe task</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\taumon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tca.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tcm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds-3.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds2-98.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds2-nt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\teekids.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tfak.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tfak5.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tgbob.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\titanin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\titaninxp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TPSrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trickler.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trjscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trjsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trojantrap3.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrustWarrior.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsadbot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tvmd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tvtmd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\undoboot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\updat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\upgrad.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\utpost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbcmserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbcons.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbust.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbwin9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbwinntw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vcsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vet32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vet95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vettray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vfsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vir-help.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\virusmdpersonalfirewall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthAux.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthLic.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthUpd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vnlan300.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vnpc3000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpc42.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpfw30s.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vptray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vscan40.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vscenu6.02d30.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsched.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsecomr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vshwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsisetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsstat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswin9xe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswinntse.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswinperse.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\w32dsm89.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\W3asbas.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\w9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\watchdog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\webdav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\WebProxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\webscanx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\webtrap.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wfindv32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\whoswatchingme.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wimmun32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\win-bugsfix.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\win32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\win32us.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winactive.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windll32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\window.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows Police Pro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wininetd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wininitx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winlogin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winppr32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winrecon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winservn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winssk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winstart.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winstart001.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wintsk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wkufind.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wnad.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wradmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wrctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsbgate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxas.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxfw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsctool.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wupdater.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wupdt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wyvernworksfirewall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpdeluxe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpf202en.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zatutor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zonalm2601.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zonealarm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~1.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-ode.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsStabilityGuard_1.png"><img class="alignnone size-medium wp-image-2912" title="Rogue.Win32.WindowsStabilityGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsStabilityGuard_1-400x234.png" alt="Rogue.Win32.WindowsStabilityGuard" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsStabilityGuard_2.png"><img class="alignnone size-medium wp-image-2913" title="Rogue.Win32.WindowsStabilityGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsStabilityGuard_2-400x293.png" alt="Rogue.Win32.WindowsStabilityGuard" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsStabilityGuard_3.png"><img class="alignnone size-medium wp-image-2914" title="Rogue.Win32.WindowsStabilityGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsStabilityGuard_3-400x293.png" alt="Rogue.Win32.WindowsStabilityGuard" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsStabilityGuard_4.png"><img class="alignnone size-medium wp-image-2915" title="Rogue.Win32.WindowsStabilityGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsStabilityGuard_4-400x238.png" alt="Rogue.Win32.WindowsStabilityGuard" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsStabilityGuard_5.png"><img class="alignnone size-medium wp-image-2916" title="Rogue.Win32.WindowsStabilityGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsStabilityGuard_5-400x253.png" alt="Rogue.Win32.WindowsStabilityGuard" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Stability Guard </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsStabilityGuard" target="_blank">Rogue.Win32.WindowsStabilityGuard</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/02/29/windows-stability-guard-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Pro Scanner Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/02/27/windows-pro-scanner-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/02/27/windows-pro-scanner-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 27 Feb 2012 08:19:24 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Pro Scanner]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2903</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Pro Scanner. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsProScanner. Windows Pro Scanner is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Pro Scanner</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsProScanner" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProScanner" target="_blank"><strong>Rogue.Win32.WindowsProScanner</strong></a><strong>.</strong></p>
<p><strong>Windows Pro Scanner </strong><strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-ajm.exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows PRO Scanner.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows PRO Scanner.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AluSchedulerSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\amon9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\anti-trojan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirus.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ants.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\apimonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aplica32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\apvxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\arr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashAvast.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashBug.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashChest.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashCnsnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashLogV.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashMaiSv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashPopWz.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashQuick.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashServ.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSimp2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSimpl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSkPcc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSkPck.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashUpd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashWebSv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswChLic.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswRegSvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswRunDll.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswUpdSv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atcon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atro55en.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atupdater.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\au.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\auto-protect.nav80try.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\autodown.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\autotrace.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avadmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avcenter.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avciman.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconfig.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconsol.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ave32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgchk.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcsrvx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgdumpx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgemc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgiproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnsx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrsx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgscanx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgserv9.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgsrmax.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgtray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgwdsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkpop.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkservice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkwctl9.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avltmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avmailc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avmcdlg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avnotify.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpcc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpdos32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avptc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avsched32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avsynmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avupgsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVWEBGRD.EXE\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwin95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwinnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwsc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupsrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxmonitor9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxmonitornt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxquar.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\b.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\backweb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bargains.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvcl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvwiz.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDInProcPatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdmcon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDMsnScan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDSurvey.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bd_professional.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\beagle.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\belt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bidef.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bidserver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bipcp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bipcpevalsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bisp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blackd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blackice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blink.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blss.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bootconf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bootwarn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\borg2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brasil.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bs120.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bspatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bundle.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bvt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\c.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cavscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccevtmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccpxysvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccSvcHst.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cdp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfgwiz.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfiadmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfiaudit.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfinet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfinet32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfpconfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfplogvw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfpupdat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\claw95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\claw95cf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\clean.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleaner.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleaner3.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleanIELow.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleanpc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\click.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmdagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmesys.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmgrdian.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmon016.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\connectionmonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\control\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpf9x206.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpfnt206.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\crashrep.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssconfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssupdat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssurf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cwnb181.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cwntdwmo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\d.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\datemanager.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dcomx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\defalert.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\defscangui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\defwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\deloeminfs.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\deputy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dllcache.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dllreg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\doors.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpfsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpps2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\driverctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\drwatson.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\drweb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\drwebupw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dssagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dvp95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dvp95_0.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ecengine.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\efpeadm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\emsw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\esafe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\escanhnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\escanv95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\espwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ethereal.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\etrustcipe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\evpn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\exantivirus-cnet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\exe.avxw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\expert.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\explore.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-agnt95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-prot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-prot95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-stopw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fact.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fameh32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fast.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fch32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fih32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\findviru.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\firewall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fixcfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fixfp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fnrb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fp-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fp-win_trial.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fprot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frmwrk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsaa.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav530stbyb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav530wtbyb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsgk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsm32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsma32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsmb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gator.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbmenu.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbpoll.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\generics.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gmt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\guard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\guarddog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\guardgui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hacktracersetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hbinst.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hbsrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\History.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\homeav2010.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hotactio.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hotpatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\htlog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\htpatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hwpe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hxdl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hxiul.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamstats.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ibmasn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ibmavsp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icload95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icloadnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icsupp95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icsuppnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Identity.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\idle.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iedll.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iedriver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\IEShow.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iface.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ifw2000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\inetlnfo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\infus.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\infwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init32.exe \<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[1].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[2].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[3].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[4].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[5].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\intdel.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\intren.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iomon98.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\istsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\jammer.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\jdbgmrg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\jedi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\JsRcGen.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavlite40eng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavpers40eng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavpf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kazza.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\keenvalue.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-pf-213-en-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-wrl-421-en-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-wrp-421-en-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\killprocesssetup161.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldnetmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldpro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldpromenu.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\licmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lnetinfo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\loader.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\localnet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lockdown.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lockdown2000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lookout.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lordpe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luau.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lucomserver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luinit.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luspt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MalwareRemoval.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mapisvc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcmnhdlr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcmscsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcnasvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\McSACore.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcshell.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcshield.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcsysmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mctool.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcvsrte.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcvsshld.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\md.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfw2en.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfweng3.02d30.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgavrtcl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgavrte.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mghtml.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\minilog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmod.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\monitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\moolive.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpfagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpfservice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MPFSrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpftray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mrflux.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mrt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msa.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msbb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msblast.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscache.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msccn32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscman.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msdm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msdos.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msiexec16.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mslaugh.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmgt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmsgri32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mssmmc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mssys.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msvxd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mu0311ad.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\n32scanw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navap.navapsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navapsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navapw32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navdx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navlu32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navstub.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navw32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navwnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nc2000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ncinst4.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ndd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\neomonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\neowatchlog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netarmor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netinfo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netscanpro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netspyhunter-1.2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netutils.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nisserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nisum.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\normist.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\norton_internet_secu_3.0_407.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\notstart.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npf40_tw_98_nt_me_2k.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npfmessenger.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nprotect.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npscheck.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npssvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nsched32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nssys32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nstask32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nsupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntrtscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntvdm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntxconfig.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nupgrade.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvarch16.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvc95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvsvc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwinst4.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwservice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwtool16.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAcat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAhlp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAReg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\oasrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\oaui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\oaview.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ODSW.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ollydbg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\onsrvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\optimize.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ostronet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\otfix.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpostinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpostproinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ozn695m5.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\padmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\panixk.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\patch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavcl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PavFnSvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavprsrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavsched.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavsrv51.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pccwin98.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcfwallicon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcip10117_0.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsAuxs.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsGui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PC_Antispyware2010.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfndr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PerAvir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\periscope.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\persfw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\perswf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pf2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pfwadmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pgmonitr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pingscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pop3trap.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\poproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\popscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\portdetective.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\portmonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ppinupdt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pptbc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ppvstop.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\prizesurfer.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\prmt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\prmvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\procdump.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\processmonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexplorerv1.0.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\programauditor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\proport.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protector.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANCU.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANHost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANToManager.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PsCtrls.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PsImSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PskSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pspf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSUNMain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\purge.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qconsole.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qh.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qserver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quick Heal.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\QuickHealCleaner.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rapapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav7.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav7win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav8win32eng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rcsync.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\realmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\reged.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe\<br />
Debugger = C:\Documents and Settings\Administrator\Application Data\Inspector-pwe.exe reg</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedt32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rescue.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rescue32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rrguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rscdwld.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rshell.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rtvscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rtvscn95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rulaunch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeweb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sahagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Save.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveArmor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveDefense.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveKeep.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\savenow.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sbserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scam32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scanpm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scrscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secure Veteran.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\secureveteran.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Security Center.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SecurityFighter.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\securitysoldier.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\serv95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\setloadorder.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\setupvameeval.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup_flowprotector_us.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sgssfw32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sh.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\shellspyinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\shield.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\shn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\showbehind.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\signcheck.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smart.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartprotector.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smrtdefp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sms.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smss32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\snetcfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\soap.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sofi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftSafeness.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sperm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sphinx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoler.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolcv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolsv32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spywarexpguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spyxx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\srexe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\srng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ss3edit.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssgrate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssg_4104.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\st2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\start.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\stcloader.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\supftrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\support.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\supporter5.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchostc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchosts.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svshost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweep95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweepnet.sweepsrv.sys.swnetsup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\symproxysvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\symtray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\system.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\system32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sysupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe\<br />
Debugger = C:\Documents and Settings\Administrator\Application Data\Inspector-pwe.exe task</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\taumon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tca.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tcm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds-3.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds2-98.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds2-nt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\teekids.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tfak.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tfak5.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tgbob.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\titanin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\titaninxp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TPSrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trickler.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trjscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trjsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trojantrap3.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrustWarrior.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsadbot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tvmd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tvtmd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\undoboot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\updat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\upgrad.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\utpost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbcmserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbcons.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbust.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbwin9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbwinntw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vcsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vet32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vet95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vettray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vfsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vir-help.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\virusmdpersonalfirewall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthAux.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthLic.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthUpd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vnlan300.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vnpc3000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpc42.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpfw30s.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vptray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vscan40.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vscenu6.02d30.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsched.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsecomr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vshwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsisetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsstat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswin9xe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswinntse.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswinperse.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\w32dsm89.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\W3asbas.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\w9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\watchdog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\webdav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\WebProxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\webscanx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\webtrap.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wfindv32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\whoswatchingme.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wimmun32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\win-bugsfix.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\win32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\win32us.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winactive.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windll32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\window.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows Police Pro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wininetd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wininitx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winlogin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winppr32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winrecon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winservn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winssk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winstart.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winstart001.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wintsk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wkufind.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wnad.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wradmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wrctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsbgate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxas.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxfw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsctool.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wupdater.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wupdt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wyvernworksfirewall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpdeluxe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpf202en.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zatutor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zonalm2601.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zonealarm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~1.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-ajm.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsProScanner_1.png"><img class="alignnone size-medium wp-image-2904" title="Rogue.Win32.WindowsProScanner" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsProScanner_1-400x234.png" alt="Rogue.Win32.WindowsProScanner" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsProScanner_2.png"><img class="alignnone size-medium wp-image-2905" title="Rogue.Win32.WindowsProScanner" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsProScanner_2-400x293.png" alt="Rogue.Win32.WindowsProScanner" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsProScanner_3.png"><img class="alignnone size-medium wp-image-2906" title="Rogue.Win32.WindowsProScanner" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsProScanner_3-400x293.png" alt="Rogue.Win32.WindowsProScanner" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsProScanner_4.png"><img class="alignnone size-medium wp-image-2907" title="Rogue.Win32.WindowsProScanner" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsProScanner_4-400x238.png" alt="Rogue.Win32.WindowsProScanner" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsProScanner_5.png"><img class="alignnone size-medium wp-image-2908" title="Rogue.Win32.WindowsProScanner" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsProScanner_5-400x253.png" alt="Rogue.Win32.WindowsProScanner" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Pro Scanner </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProScanner" target="_blank">Rogue.Win32.WindowsProScanner</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/02/27/windows-pro-scanner-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Shield Tool Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/02/24/windows-shield-tool-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/02/24/windows-shield-tool-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 24 Feb 2012 14:58:21 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Shield Tool]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2895</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Shield Tool. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsShieldTool. Windows Shield Tool is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Shield Tool</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsShieldTool" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldTool" target="_blank"><strong>Rogue.Win32.WindowsShieldTool</strong></a><strong>.</strong></p>
<p><strong>Windows Shield Tool </strong><strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-lra.exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Shield Tool.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Shield Tool.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AluSchedulerSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\amon9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\anti-trojan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirus.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ants.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\apimonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aplica32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\apvxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\arr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashAvast.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashBug.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashChest.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashCnsnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashLogV.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashMaiSv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashPopWz.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashQuick.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashServ.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSimp2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSimpl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSkPcc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSkPck.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashUpd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashWebSv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswChLic.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswRegSvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswRunDll.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswUpdSv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atcon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atro55en.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atupdater.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\au.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\auto-protect.nav80try.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\autodown.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\autotrace.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avadmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avcenter.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avciman.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconfig.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconsol.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ave32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgchk.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcsrvx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgdumpx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgemc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgiproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnsx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrsx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgscanx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgserv9.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgsrmax.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgtray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgwdsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkpop.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkservice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkwctl9.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avltmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avmailc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avmcdlg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avnotify.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpcc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpdos32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avptc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avsched32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avsynmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avupgsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVWEBGRD.EXE\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwin95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwinnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwsc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupsrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxmonitor9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxmonitornt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxquar.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\b.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\backweb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bargains.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvcl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvwiz.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDInProcPatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdmcon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDMsnScan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDSurvey.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bd_professional.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\beagle.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\belt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bidef.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bidserver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bipcp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bipcpevalsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bisp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blackd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blackice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blink.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blss.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bootconf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bootwarn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\borg2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brasil.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bs120.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bspatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bundle.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bvt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\c.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cavscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccevtmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccpxysvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccSvcHst.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cdp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfgwiz.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfiadmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfiaudit.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfinet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfinet32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfpconfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfplogvw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfpupdat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\claw95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\claw95cf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\clean.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleaner.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleaner3.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleanIELow.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleanpc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\click.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmdagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmesys.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmgrdian.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmon016.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\connectionmonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\control\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpf9x206.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpfnt206.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\crashrep.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssconfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssupdat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssurf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cwnb181.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cwntdwmo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\d.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\datemanager.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dcomx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\defalert.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\defscangui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\defwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\deloeminfs.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\deputy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dllcache.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dllreg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\doors.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpfsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpps2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\driverctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\drwatson.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\drweb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\drwebupw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dssagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dvp95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dvp95_0.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ecengine.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\efpeadm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\emsw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\esafe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\escanhnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\escanv95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\espwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ethereal.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\etrustcipe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\evpn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\exantivirus-cnet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\exe.avxw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\expert.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\explore.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-agnt95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-prot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-prot95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-stopw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fact.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fameh32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fast.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fch32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fih32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\findviru.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\firewall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fixcfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fixfp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fnrb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fp-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fp-win_trial.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fprot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frmwrk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsaa.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav530stbyb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav530wtbyb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsgk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsm32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsma32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsmb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gator.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbmenu.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbpoll.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\generics.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gmt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\guard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\guarddog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\guardgui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hacktracersetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hbinst.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hbsrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\History.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\homeav2010.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hotactio.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hotpatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\htlog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\htpatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hwpe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hxdl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hxiul.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamstats.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ibmasn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ibmavsp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icload95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icloadnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icsupp95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icsuppnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Identity.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\idle.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iedll.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iedriver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\IEShow.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iface.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ifw2000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\inetlnfo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\infus.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\infwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init32.exe \<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[1].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[2].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[3].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[4].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[5].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\intdel.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\intren.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iomon98.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\istsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\jammer.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\jdbgmrg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\jedi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\JsRcGen.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavlite40eng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavpers40eng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavpf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kazza.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\keenvalue.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-pf-213-en-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-wrl-421-en-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-wrp-421-en-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\killprocesssetup161.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldnetmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldpro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldpromenu.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\licmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lnetinfo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\loader.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\localnet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lockdown.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lockdown2000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lookout.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lordpe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luau.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lucomserver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luinit.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luspt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MalwareRemoval.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mapisvc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcmnhdlr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcmscsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcnasvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\McSACore.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcshell.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcshield.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcsysmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mctool.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcvsrte.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcvsshld.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\md.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfw2en.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfweng3.02d30.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgavrtcl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgavrte.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mghtml.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\minilog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmod.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\monitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\moolive.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpfagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpfservice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MPFSrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpftray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mrflux.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mrt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msa.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msbb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msblast.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscache.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msccn32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscman.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msdm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msdos.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msiexec16.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mslaugh.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmgt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmsgri32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mssmmc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mssys.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msvxd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mu0311ad.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\n32scanw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navap.navapsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navapsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navapw32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navdx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navlu32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navstub.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navw32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navwnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nc2000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ncinst4.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ndd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\neomonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\neowatchlog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netarmor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netinfo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netscanpro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netspyhunter-1.2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netutils.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nisserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nisum.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\normist.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\norton_internet_secu_3.0_407.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\notstart.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npf40_tw_98_nt_me_2k.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npfmessenger.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nprotect.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npscheck.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npssvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nsched32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nssys32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nstask32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nsupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntrtscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntvdm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntxconfig.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nupgrade.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvarch16.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvc95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvsvc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwinst4.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwservice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwtool16.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAcat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAhlp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAReg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\oasrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\oaui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\oaview.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ODSW.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ollydbg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\onsrvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\optimize.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ostronet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\otfix.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpostinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpostproinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ozn695m5.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\padmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\panixk.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\patch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavcl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PavFnSvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavprsrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavsched.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavsrv51.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pccwin98.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcfwallicon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcip10117_0.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsAuxs.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsGui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PC_Antispyware2010.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfndr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PerAvir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\periscope.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\persfw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\perswf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pf2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pfwadmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pgmonitr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pingscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pop3trap.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\poproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\popscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\portdetective.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\portmonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ppinupdt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pptbc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ppvstop.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\prizesurfer.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\prmt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\prmvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\procdump.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\processmonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexplorerv1.0.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\programauditor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\proport.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protector.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANCU.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANHost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANToManager.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PsCtrls.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PsImSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PskSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pspf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSUNMain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\purge.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qconsole.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qh.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qserver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quick Heal.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\QuickHealCleaner.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rapapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav7.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav7win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav8win32eng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rcsync.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\realmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\reged.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe\<br />
Debugger = C:\Documents and Settings\Administrator\Application Data\Inspector-pwe.exe reg</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedt32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rescue.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rescue32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rrguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rscdwld.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rshell.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rtvscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rtvscn95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rulaunch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeweb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sahagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Save.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveArmor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveDefense.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveKeep.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\savenow.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sbserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scam32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scanpm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scrscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secure Veteran.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\secureveteran.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Security Center.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SecurityFighter.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\securitysoldier.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\serv95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\setloadorder.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\setupvameeval.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup_flowprotector_us.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sgssfw32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sh.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\shellspyinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\shield.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\shn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\showbehind.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\signcheck.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smart.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartprotector.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smrtdefp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sms.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smss32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\snetcfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\soap.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sofi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftSafeness.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sperm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sphinx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoler.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolcv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolsv32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spywarexpguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spyxx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\srexe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\srng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ss3edit.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssgrate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssg_4104.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\st2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\start.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\stcloader.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\supftrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\support.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\supporter5.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchostc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchosts.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svshost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweep95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweepnet.sweepsrv.sys.swnetsup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\symproxysvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\symtray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\system.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\system32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sysupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe\<br />
Debugger = C:\Documents and Settings\Administrator\Application Data\Inspector-pwe.exe task</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\taumon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tca.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tcm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds-3.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds2-98.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds2-nt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\teekids.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tfak.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tfak5.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tgbob.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\titanin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\titaninxp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TPSrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trickler.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trjscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trjsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trojantrap3.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrustWarrior.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsadbot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tvmd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tvtmd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\undoboot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\updat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\upgrad.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\utpost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbcmserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbcons.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbust.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbwin9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbwinntw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vcsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vet32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vet95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vettray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vfsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vir-help.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\virusmdpersonalfirewall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthAux.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthLic.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthUpd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vnlan300.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vnpc3000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpc42.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpfw30s.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vptray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vscan40.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vscenu6.02d30.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsched.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsecomr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vshwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsisetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsstat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswin9xe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswinntse.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswinperse.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\w32dsm89.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\W3asbas.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\w9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\watchdog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\webdav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\WebProxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\webscanx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\webtrap.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wfindv32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\whoswatchingme.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wimmun32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\win-bugsfix.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\win32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\win32us.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winactive.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windll32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\window.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows Police Pro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wininetd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wininitx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winlogin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winppr32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winrecon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winservn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winssk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winstart.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winstart001.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wintsk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wkufind.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wnad.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wradmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wrctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsbgate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxas.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxfw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsctool.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wupdater.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wupdt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wyvernworksfirewall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpdeluxe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpf202en.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zatutor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zonalm2601.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zonealarm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~1.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-lra.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsShieldTool_1.png"><img class="alignnone size-medium wp-image-2896" title="Rogue.Win32.WindowsShieldTool" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsShieldTool_1-400x234.png" alt="Rogue.Win32.WindowsShieldTool" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsShieldTool_2.png"><img class="alignnone size-medium wp-image-2897" title="Rogue.Win32.WindowsShieldTool" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsShieldTool_2-400x293.png" alt="Rogue.Win32.WindowsShieldTool" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsShieldTool_31.png"><img class="alignnone size-medium wp-image-2899" title="Rogue.Win32.WindowsShieldTool" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsShieldTool_31-400x293.png" alt="Rogue.Win32.WindowsShieldTool" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsShieldTool_4.png"><img class="alignnone size-medium wp-image-2900" title="Rogue.Win32.WindowsShieldTool" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsShieldTool_4-400x238.png" alt="Rogue.Win32.WindowsShieldTool" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsShieldTool_5.png"><img class="alignnone size-medium wp-image-2901" title="Rogue.Win32.WindowsShieldTool" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsShieldTool_5-400x253.png" alt="Rogue.Win32.WindowsShieldTool" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Shield Tool </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsShieldTool" target="_blank">Rogue.Win32.WindowsShieldTool</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/02/24/windows-shield-tool-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Telemetry Center Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/02/23/windows-telemetry-center-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/02/23/windows-telemetry-center-rogue-removal-instructions/#comments</comments>
		<pubDate>Thu, 23 Feb 2012 07:55:52 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Telemetry Center]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2885</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Telemetry Center. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsTelemetryCenter. Windows Telemetry Center is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Telemetry Center</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsTelemetryCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTelemetryCenter" target="_blank"><strong>Rogue.Win32.WindowsTelemetryCenter</strong></a><strong>.</strong></p>
<p><strong>Windows Telemetry Center </strong><strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-cnr.exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Telemetry Center.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Telemetry Center.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AluSchedulerSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\amon9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\anti-trojan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirus.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ants.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\apimonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aplica32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\apvxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\arr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashAvast.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashBug.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashChest.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashCnsnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashLogV.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashMaiSv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashPopWz.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashQuick.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashServ.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSimp2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSimpl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSkPcc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSkPck.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashUpd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashWebSv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswChLic.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswRegSvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswRunDll.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswUpdSv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atcon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atro55en.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atupdater.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\au.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\auto-protect.nav80try.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\autodown.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\autotrace.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avadmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avcenter.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avciman.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconfig.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconsol.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ave32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgchk.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcsrvx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgdumpx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgemc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgiproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnsx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrsx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgscanx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgserv9.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgsrmax.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgtray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgwdsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkpop.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkservice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkwctl9.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avltmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avmailc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avmcdlg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avnotify.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpcc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpdos32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avptc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avsched32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avsynmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avupgsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVWEBGRD.EXE\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwin95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwinnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwsc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupsrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxmonitor9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxmonitornt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxquar.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\b.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\backweb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bargains.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvcl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvwiz.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDInProcPatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdmcon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDMsnScan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDSurvey.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bd_professional.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\beagle.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\belt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bidef.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bidserver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bipcp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bipcpevalsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bisp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blackd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blackice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blink.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blss.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bootconf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bootwarn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\borg2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brasil.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bs120.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bspatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bundle.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bvt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\c.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cavscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccevtmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccpxysvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccSvcHst.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cdp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfgwiz.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfiadmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfiaudit.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfinet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfinet32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfpconfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfplogvw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfpupdat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\claw95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\claw95cf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\clean.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleaner.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleaner3.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleanIELow.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleanpc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\click.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmdagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmesys.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmgrdian.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmon016.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\connectionmonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\control\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpf9x206.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpfnt206.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\crashrep.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssconfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssupdat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssurf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cwnb181.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cwntdwmo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\d.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\datemanager.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dcomx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\defalert.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\defscangui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\defwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\deloeminfs.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\deputy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dllcache.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dllreg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\doors.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpfsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpps2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\driverctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\drwatson.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\drweb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\drwebupw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dssagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dvp95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dvp95_0.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ecengine.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\efpeadm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\emsw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\esafe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\escanhnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\escanv95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\espwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ethereal.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\etrustcipe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\evpn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\exantivirus-cnet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\exe.avxw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\expert.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\explore.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-agnt95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-prot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-prot95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-stopw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fact.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fameh32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fast.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fch32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fih32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\findviru.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\firewall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fixcfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fixfp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fnrb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fp-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fp-win_trial.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fprot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frmwrk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsaa.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav530stbyb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav530wtbyb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsgk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsm32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsma32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsmb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gator.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbmenu.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbpoll.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\generics.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gmt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\guard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\guarddog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\guardgui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hacktracersetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hbinst.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hbsrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\History.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\homeav2010.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hotactio.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hotpatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\htlog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\htpatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hwpe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hxdl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hxiul.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamstats.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ibmasn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ibmavsp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icload95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icloadnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icsupp95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icsuppnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Identity.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\idle.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iedll.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iedriver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\IEShow.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iface.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ifw2000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\inetlnfo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\infus.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\infwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init32.exe \<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[1].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[2].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[3].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[4].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[5].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\intdel.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\intren.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iomon98.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\istsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\jammer.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\jdbgmrg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\jedi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\JsRcGen.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavlite40eng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavpers40eng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavpf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kazza.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\keenvalue.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-pf-213-en-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-wrl-421-en-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-wrp-421-en-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\killprocesssetup161.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldnetmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldpro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldpromenu.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\licmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lnetinfo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\loader.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\localnet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lockdown.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lockdown2000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lookout.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lordpe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luau.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lucomserver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luinit.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luspt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MalwareRemoval.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mapisvc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcmnhdlr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcmscsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcnasvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\McSACore.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcshell.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcshield.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcsysmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mctool.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcvsrte.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcvsshld.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\md.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfw2en.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfweng3.02d30.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgavrtcl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgavrte.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mghtml.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\minilog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmod.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\monitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\moolive.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpfagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpfservice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MPFSrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpftray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mrflux.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mrt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msa.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msbb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msblast.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscache.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msccn32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscman.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msdm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msdos.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msiexec16.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mslaugh.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmgt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmsgri32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mssmmc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mssys.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msvxd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mu0311ad.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\n32scanw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navap.navapsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navapsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navapw32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navdx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navlu32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navstub.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navw32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navwnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nc2000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ncinst4.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ndd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\neomonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\neowatchlog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netarmor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netinfo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netscanpro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netspyhunter-1.2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netutils.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nisserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nisum.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\normist.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\norton_internet_secu_3.0_407.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\notstart.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npf40_tw_98_nt_me_2k.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npfmessenger.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nprotect.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npscheck.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npssvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nsched32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nssys32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nstask32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nsupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntrtscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntvdm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntxconfig.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nupgrade.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvarch16.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvc95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvsvc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwinst4.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwservice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwtool16.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAcat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAhlp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAReg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\oasrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\oaui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\oaview.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ODSW.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ollydbg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\onsrvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\optimize.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ostronet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\otfix.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpostinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpostproinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ozn695m5.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\padmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\panixk.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\patch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavcl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PavFnSvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavprsrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavsched.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavsrv51.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pccwin98.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcfwallicon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcip10117_0.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsAuxs.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsGui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PC_Antispyware2010.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfndr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PerAvir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\periscope.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\persfw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\perswf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pf2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pfwadmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pgmonitr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pingscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pop3trap.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\poproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\popscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\portdetective.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\portmonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ppinupdt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pptbc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ppvstop.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\prizesurfer.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\prmt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\prmvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\procdump.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\processmonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexplorerv1.0.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\programauditor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\proport.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protector.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANCU.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANHost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANToManager.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PsCtrls.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PsImSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PskSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pspf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSUNMain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\purge.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qconsole.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qh.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qserver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quick Heal.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\QuickHealCleaner.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rapapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav7.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav7win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav8win32eng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rcsync.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\realmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\reged.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe\<br />
Debugger = C:\Documents and Settings\Administrator\Application Data\Inspector-pwe.exe reg</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedt32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rescue.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rescue32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rrguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rscdwld.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rshell.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rtvscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rtvscn95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rulaunch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeweb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sahagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Save.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveArmor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveDefense.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveKeep.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\savenow.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sbserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scam32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scanpm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scrscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secure Veteran.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\secureveteran.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Security Center.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SecurityFighter.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\securitysoldier.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\serv95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\setloadorder.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\setupvameeval.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup_flowprotector_us.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sgssfw32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sh.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\shellspyinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\shield.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\shn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\showbehind.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\signcheck.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smart.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartprotector.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smrtdefp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sms.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smss32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\snetcfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\soap.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sofi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftSafeness.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sperm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sphinx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoler.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolcv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolsv32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spywarexpguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spyxx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\srexe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\srng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ss3edit.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssgrate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssg_4104.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\st2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\start.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\stcloader.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\supftrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\support.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\supporter5.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchostc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchosts.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svshost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweep95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweepnet.sweepsrv.sys.swnetsup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\symproxysvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\symtray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\system.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\system32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sysupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe\<br />
Debugger = C:\Documents and Settings\Administrator\Application Data\Inspector-pwe.exe task</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\taumon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tca.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tcm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds-3.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds2-98.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds2-nt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\teekids.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tfak.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tfak5.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tgbob.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\titanin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\titaninxp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TPSrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trickler.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trjscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trjsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trojantrap3.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrustWarrior.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsadbot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tvmd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tvtmd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\undoboot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\updat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\upgrad.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\utpost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbcmserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbcons.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbust.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbwin9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbwinntw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vcsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vet32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vet95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vettray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vfsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vir-help.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\virusmdpersonalfirewall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthAux.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthLic.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthUpd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vnlan300.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vnpc3000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpc42.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpfw30s.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vptray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vscan40.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vscenu6.02d30.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsched.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsecomr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vshwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsisetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsstat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswin9xe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswinntse.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswinperse.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\w32dsm89.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\W3asbas.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\w9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\watchdog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\webdav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\WebProxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\webscanx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\webtrap.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wfindv32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\whoswatchingme.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wimmun32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\win-bugsfix.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\win32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\win32us.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winactive.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windll32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\window.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows Police Pro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wininetd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wininitx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winlogin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winppr32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winrecon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winservn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winssk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winstart.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winstart001.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wintsk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wkufind.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wnad.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wradmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wrctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsbgate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxas.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxfw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsctool.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wupdater.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wupdt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wyvernworksfirewall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpdeluxe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpf202en.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zatutor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zonalm2601.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zonealarm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~1.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-cnr.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsTelemetryCenter_1.png"><img class="alignnone size-medium wp-image-2886" title="Rogue.Win32.WindowsTelemetryCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsTelemetryCenter_1-400x234.png" alt="Rogue.Win32.WindowsTelemetryCenter" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsTelemetryCenter_2.png"><img class="alignnone size-medium wp-image-2887" title="Rogue.Win32.WindowsTelemetryCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsTelemetryCenter_2-400x293.png" alt="Rogue.Win32.WindowsTelemetryCenter" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsTelemetryCenter_3.png"><img class="alignnone size-medium wp-image-2888" title="Rogue.Win32.WindowsTelemetryCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsTelemetryCenter_3-400x293.png" alt="Rogue.Win32.WindowsTelemetryCenter" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsTelemetryCenter_4.png"><img class="alignnone size-medium wp-image-2889" title="Rogue.Win32.WindowsTelemetryCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsTelemetryCenter_4-400x238.png" alt="Rogue.Win32.WindowsTelemetryCenter" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsTelemetryCenter_5.png"><img class="alignnone size-medium wp-image-2890" title="Rogue.Win32.WindowsTelemetryCenter" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsTelemetryCenter_5-400x253.png" alt="Rogue.Win32.WindowsTelemetryCenter" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Telemetry Center </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsTelemetryCenter" target="_blank">Rogue.Win32.WindowsTelemetryCenter</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/02/23/windows-telemetry-center-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Antivirus Protection 2012 Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/02/22/antivirus-protection-2012-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/02/22/antivirus-protection-2012-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 22 Feb 2012 07:38:43 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Antivirus Protection 2012]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2877</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Antivirus Protection 2012. Emsisoft Anti-Malware detects this malware as Rogue.Win32.AntivirusProtection2012. Antivirus Protection 2012 is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Antivirus Protection 2012</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.AntivirusProtection2012" href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirusProtection2012" target="_blank"><strong>Rogue.Win32.AntivirusProtection2012</strong></a><strong>.</strong></p>
<p><strong>Antivirus Protection 2012 </strong><strong> </strong>is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Antivirus Protection\</li>
<li>%AppData%\Antivirus Protection\IcoActivate.ico</li>
<li>%AppData%\Antivirus Protection\IcoHelp.ico</li>
<li>%AppData%\Antivirus Protection\IcoUninstall.ico</li>
<li>%AppData%\Antivirus Protection\securityhelper.exe</li>
<li>%AppData%\Antivirus Protection\securitymanager.exe</li>
<li>%AppData%\Antivirus Protection\AntivirusProtection2012.exe</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\Antivirus Protection.lnk</li>
<li>%UserProfile%\Desktop\Antivirus Protection.lnk</li>
<li>%Temp%\472a10e2ebxd9.exe</li>
<li>%Temp%\56493.exe</li>
<li>%Temp%\ae0965a7157cd.exe</li>
<li>%Temp%\al3erfa3.exe</li>
<li>%Temp%\alerfa2.exe</li>
<li>%Temp%\alerfa.exe</li>
<li>%Temp%\altedf.exe</li>
<li>%Temp%\aqfitrlxi2.exe</li>
<li>%Temp%\backd-efq.exe</li>
<li>%Temp%\brdss.exe</li>
<li>%Temp%\bzqa43d.exe</li>
<li>%Temp%\cffd4.exe</li>
<li>%Temp%\cocksucker.exe</li>
<li>%Temp%\cosock.exe</li>
<li>%Temp%\cowceb.exe</li>
<li>%Temp%\cunifuc.exe</li>
<li>%Temp%\d20mes.exe</li>
<li>%Temp%\dc_3.exe</li>
<li>%Temp%\dd10x10.exe</li>
<li>%Temp%\ddoll3342.exe</li>
<li>%Temp%\destroyer.exe</li>
<li>%Temp%\dffuck.exe</li>
<li>%Temp%\dkfjd93.exe</li>
<li>%Temp%\ds7hw.exe</li>
<li>%Temp%\eelnvd13.exe</li>
<li>%Temp%\exppdf_w.exe</li>
<li>%Temp%\fadz43.exe</li>
<li>%Temp%\fe.exe</li>
<li>%Temp%\format.exe</li>
<li>%Temp%\g_dx234.exe</li>
<li>%Temp%\ggwwef9752.exe</li>
<li>%Temp%\gpupz2a.exe</li>
<li>%Temp%\hhbboll_2.exe</li>
<li>%Temp%\hiphop.exe</li>
<li>%Temp%\hodeme.exe</li>
<li>%Temp%\htfad4.exe</li>
<li>%Temp%\hvipws9.exe</li>
<li>%Temp%\jdhellwo3.exe</li>
<li>%Temp%\jkfuckfu.exe</li>
<li>%Temp%\jofcdks.exe</li>
<li>%Temp%\kjdh_gf_jjdhgd.exe</li>
<li>%Temp%\kjh102k3.exe</li>
<li>%Temp%\kn.a.exe</li>
<li>%Temp%\kock.exe</li>
<li>%Temp%\ljts-23.exe</li>
<li>%Temp%\lkhgg_ea.exe</li>
<li>%Temp%\lols.exe</li>
<li>%Temp%\ploper.exe</li>
<li>%Temp%\poertd.exe</li>
<li>%Temp%\ppddfcfux.exxe</li>
<li>%Temp%\protector2.exe</li>
<li>%Temp%\pswwg3c.exe</li>
<li>%Temp%\puzpup.exe</li>
<li>%Temp%\qwedvor.exe</li>
<li>%Temp%\qwklrvjhqlkj.exe</li>
<li>%Temp%\r0life.exe</li>
<li>%Temp%\rator.exe</li>
<li>%Temp%\rtfme.exe</li>
<li>%Temp%\safe.exe</li>
<li>%Temp%\snowif.exe</li>
<li>%Temp%\sycre.exe</li>
<li>%Temp%\timem.exe</li>
<li>%Temp%\tryh-blv.exe</li>
<li>%Temp%\w32-reno-c.exe</li>
<li>%Temp%\w32rim_mem.exe</li>
<li>%Temp%\warsddd_w.exe</li>
<li>%Temp%\wefgetn_00.exe</li>
<li>%Temp%\wined.exe</li>
<li>%Temp%\winifi.exe</li>
<li>%Temp%\wrcud12.exe</li>
<li>%Temp%\wrfwe_di.exe</li>
<li>%Temp%\wwautrsd.exe</li>
<li>%Temp%\wwwsssgen.exe</li>
<li>%Temp%\_5.tmp</li>
<li>%Temp%\1iowieoo.exe</li>
<li>%Temp%\02c9c3c35bdx5.exe</li>
<li>%Temp%\8gmsed-bd.exe</li>
<li>%Temp%\17dkf.exe</li>
<li>%UserProfile%\Start Menu\Programs\Antivirus Protection.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Antivirus Protection\</li>
<li>%UserProfile%\Start Menu\Programs\Antivirus Protection\Antivirus Protection.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Antivirus Protection\Help Antivirus Protection.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Antivirus Protection\How to Activate Antivirus Protection.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Antivirus Protection\Activate Antivirus Protection.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Antivirus Protection\<br />
(Default)  = %AppData%\Antivirus Protection\<br />
BuyUrl = B65B17E3F9DA41446905D3BE0E550632B225D0DB132371E38F96D84D2B2F0<br />
uninstaller = %AppData%\Antivirus Protection\securityhelper.exe<br />
ADVid = 390<br />
InstallDir = %AppData%\Antivirus Protection\<br />
SoftID = Antivirus Protection<br />
ScanSystemOnStartup = 01000000<br />
AutomaticallyUpdates = 01000000<br />
BackgroundScan = 01000000<br />
BackgroundScanTimeout = 01000000<br />
tb = DC07020003001600060012002800BF02<br />
InstNM = %AppData%\Antivirus Protection\AntivirusProtection2012.exe<br />
LastTimeStamp = D9FFFFFF<br />
LastUpdateDate = 2012/2/1</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Uninstall\Antivirus Protection\<br />
DisplayName = Antivirus Protection<br />
UninstallString = &#8220;%AppData%\Antivirus Protection\securityhelper.exe&#8221; /UNINSTALL<br />
DisplayIcon = &#8220;%AppData%\Antivirus Protection\securityhelper.exe&#8221;,1</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\<br />
cbrdwlurumf5 = D:\!Mal\123.exe<br />
Antivirus Protection = &#8220;%AppData%\Antivirus Protection\AntivirusProtection2012.exe&#8221; /STARTUP<br />
Antivirus Protection 2012 SM = %AppData%\Antivirus Protection\securitymanager.exe</li>
</ul>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.AntivirusProtection2012_1.png"><img class="alignnone size-medium wp-image-2878" title="Rogue.Win32.AntivirusProtection2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.AntivirusProtection2012_1-400x319.png" alt="Rogue.Win32.AntivirusProtection2012" width="400" height="319" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.AntivirusProtection2012_2.png"><img class="alignnone size-medium wp-image-2879" title="Rogue.Win32.AntivirusProtection2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.AntivirusProtection2012_2-400x315.png" alt="Rogue.Win32.AntivirusProtection2012" width="400" height="315" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.AntivirusProtection2012_3.png"><img class="alignnone size-medium wp-image-2880" title="Rogue.Win32.AntivirusProtection2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.AntivirusProtection2012_3-400x358.png" alt="Rogue.Win32.AntivirusProtection2012" width="400" height="358" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.AntivirusProtection2012_4.png"><img class="alignnone size-medium wp-image-2881" title="Rogue.Win32.AntivirusProtection2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.AntivirusProtection2012_4-400x211.png" alt="Rogue.Win32.AntivirusProtection2012" width="400" height="211" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>LIC-00A5-3F5G-BHA5-KJB8-579F-CVH9-M935-QW45-89M5-19AB</strong></span></pre>
<p><strong>How to remove the infection of Antivirus Protection 2012 </strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirusProtection2012" target="_blank">Rogue.Win32.AntivirusProtection2012</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/12/14/security-monitor-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Security Monitor 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/10/09/antivirus-studio-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">AntiVirus Studio 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/10/protection-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Protection Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/cloud-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Cloud Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/19/av-protection-online-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Protection Online Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/02/22/antivirus-protection-2012-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Smart Partner Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/02/21/windows-smart-partner-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/02/21/windows-smart-partner-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 21 Feb 2012 13:21:00 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Smart Partner]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2868</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Smart Partner. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsSmartPartner. Windows Smart Partner is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Smart Partner</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsSmartPartner" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSmartPartner" target="_blank"><strong>Rogue.Win32.WindowsSmartPartner</strong></a><strong>.</strong></p>
<p><strong>Windows Smart Partner </strong><strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-phk.exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Smart Partner.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Smart Partner.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AluSchedulerSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\amon9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\anti-trojan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirus.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ants.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\apimonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aplica32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\apvxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\arr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashAvast.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashBug.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashChest.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashCnsnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashLogV.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashMaiSv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashPopWz.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashQuick.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashServ.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSimp2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSimpl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSkPcc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSkPck.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashUpd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashWebSv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswChLic.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswRegSvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswRunDll.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswUpdSv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atcon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atro55en.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atupdater.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\au.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\auto-protect.nav80try.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\autodown.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\autotrace.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avadmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avcenter.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avciman.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconfig.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconsol.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ave32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgchk.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcsrvx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgdumpx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgemc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgiproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnsx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrsx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgscanx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgserv9.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgsrmax.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgtray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgwdsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkpop.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkservice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkwctl9.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avltmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avmailc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avmcdlg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avnotify.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpcc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpdos32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avptc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avsched32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avsynmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avupgsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVWEBGRD.EXE\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwin95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwinnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwsc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupsrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxmonitor9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxmonitornt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxquar.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\b.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\backweb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bargains.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvcl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvwiz.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDInProcPatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdmcon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDMsnScan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDSurvey.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bd_professional.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\beagle.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\belt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bidef.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bidserver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bipcp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bipcpevalsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bisp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blackd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blackice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blink.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blss.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bootconf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bootwarn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\borg2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brasil.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bs120.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bspatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bundle.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bvt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\c.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cavscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccevtmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccpxysvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccSvcHst.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cdp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfgwiz.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfiadmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfiaudit.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfinet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfinet32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfpconfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfplogvw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfpupdat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\claw95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\claw95cf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\clean.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleaner.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleaner3.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleanIELow.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleanpc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\click.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmdagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmesys.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmgrdian.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmon016.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\connectionmonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\control\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpf9x206.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpfnt206.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\crashrep.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssconfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssupdat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssurf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cwnb181.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cwntdwmo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\d.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\datemanager.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dcomx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\defalert.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\defscangui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\defwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\deloeminfs.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\deputy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dllcache.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dllreg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\doors.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpfsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpps2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\driverctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\drwatson.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\drweb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\drwebupw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dssagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dvp95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dvp95_0.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ecengine.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\efpeadm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\emsw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\esafe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\escanhnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\escanv95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\espwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ethereal.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\etrustcipe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\evpn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\exantivirus-cnet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\exe.avxw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\expert.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\explore.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-agnt95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-prot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-prot95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-stopw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fact.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fameh32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fast.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fch32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fih32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\findviru.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\firewall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fixcfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fixfp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fnrb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fp-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fp-win_trial.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fprot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frmwrk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsaa.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav530stbyb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav530wtbyb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsgk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsm32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsma32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsmb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gator.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbmenu.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbpoll.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\generics.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gmt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\guard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\guarddog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\guardgui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hacktracersetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hbinst.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hbsrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\History.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\homeav2010.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hotactio.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hotpatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\htlog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\htpatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hwpe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hxdl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hxiul.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamstats.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ibmasn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ibmavsp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icload95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icloadnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icsupp95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icsuppnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Identity.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\idle.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iedll.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iedriver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\IEShow.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iface.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ifw2000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\inetlnfo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\infus.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\infwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init32.exe \<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[1].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[2].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[3].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[4].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[5].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\intdel.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\intren.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iomon98.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\istsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\jammer.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\jdbgmrg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\jedi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\JsRcGen.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavlite40eng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavpers40eng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavpf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kazza.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\keenvalue.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-pf-213-en-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-wrl-421-en-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-wrp-421-en-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\killprocesssetup161.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldnetmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldpro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldpromenu.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\licmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lnetinfo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\loader.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\localnet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lockdown.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lockdown2000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lookout.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lordpe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luau.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lucomserver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luinit.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luspt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MalwareRemoval.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mapisvc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcmnhdlr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcmscsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcnasvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\McSACore.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcshell.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcshield.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcsysmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mctool.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcvsrte.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcvsshld.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\md.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfw2en.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfweng3.02d30.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgavrtcl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgavrte.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mghtml.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\minilog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmod.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\monitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\moolive.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpfagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpfservice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MPFSrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpftray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mrflux.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mrt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msa.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msbb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msblast.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscache.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msccn32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscman.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msdm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msdos.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msiexec16.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mslaugh.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmgt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmsgri32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mssmmc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mssys.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msvxd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mu0311ad.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\n32scanw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navap.navapsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navapsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navapw32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navdx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navlu32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navstub.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navw32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navwnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nc2000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ncinst4.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ndd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\neomonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\neowatchlog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netarmor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netinfo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netscanpro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netspyhunter-1.2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netutils.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nisserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nisum.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\normist.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\norton_internet_secu_3.0_407.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\notstart.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npf40_tw_98_nt_me_2k.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npfmessenger.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nprotect.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npscheck.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npssvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nsched32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nssys32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nstask32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nsupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntrtscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntvdm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntxconfig.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nupgrade.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvarch16.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvc95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvsvc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwinst4.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwservice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwtool16.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAcat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAhlp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAReg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\oasrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\oaui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\oaview.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ODSW.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ollydbg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\onsrvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\optimize.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ostronet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\otfix.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpostinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpostproinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ozn695m5.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\padmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\panixk.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\patch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavcl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PavFnSvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavprsrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavsched.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavsrv51.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pccwin98.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcfwallicon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcip10117_0.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsAuxs.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsGui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PC_Antispyware2010.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfndr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PerAvir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\periscope.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\persfw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\perswf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pf2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pfwadmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pgmonitr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pingscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pop3trap.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\poproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\popscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\portdetective.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\portmonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ppinupdt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pptbc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ppvstop.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\prizesurfer.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\prmt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\prmvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\procdump.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\processmonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexplorerv1.0.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\programauditor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\proport.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protector.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANCU.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANHost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANToManager.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PsCtrls.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PsImSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PskSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pspf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSUNMain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\purge.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qconsole.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qh.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qserver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quick Heal.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\QuickHealCleaner.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rapapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav7.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav7win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav8win32eng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rcsync.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\realmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\reged.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe\<br />
Debugger = C:\Documents and Settings\Administrator\Application Data\Inspector-pwe.exe reg</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedt32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rescue.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rescue32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rrguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rscdwld.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rshell.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rtvscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rtvscn95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rulaunch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeweb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sahagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Save.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveArmor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveDefense.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveKeep.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\savenow.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sbserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scam32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scanpm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scrscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secure Veteran.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\secureveteran.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Security Center.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SecurityFighter.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\securitysoldier.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\serv95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\setloadorder.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\setupvameeval.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup_flowprotector_us.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sgssfw32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sh.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\shellspyinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\shield.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\shn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\showbehind.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\signcheck.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smart.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartprotector.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smrtdefp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sms.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smss32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\snetcfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\soap.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sofi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftSafeness.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sperm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sphinx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoler.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolcv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolsv32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spywarexpguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spyxx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\srexe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\srng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ss3edit.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssgrate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssg_4104.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\st2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\start.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\stcloader.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\supftrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\support.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\supporter5.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchostc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchosts.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svshost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweep95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweepnet.sweepsrv.sys.swnetsup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\symproxysvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\symtray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\system.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\system32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sysupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe\<br />
Debugger = C:\Documents and Settings\Administrator\Application Data\Inspector-pwe.exe task</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\taumon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tca.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tcm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds-3.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds2-98.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds2-nt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\teekids.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tfak.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tfak5.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tgbob.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\titanin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\titaninxp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TPSrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trickler.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trjscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trjsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trojantrap3.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrustWarrior.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsadbot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tvmd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tvtmd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\undoboot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\updat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\upgrad.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\utpost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbcmserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbcons.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbust.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbwin9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbwinntw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vcsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vet32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vet95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vettray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vfsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vir-help.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\virusmdpersonalfirewall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthAux.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthLic.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthUpd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vnlan300.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vnpc3000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpc42.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpfw30s.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vptray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vscan40.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vscenu6.02d30.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsched.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsecomr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vshwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsisetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsstat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswin9xe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswinntse.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswinperse.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\w32dsm89.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\W3asbas.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\w9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\watchdog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\webdav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\WebProxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\webscanx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\webtrap.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wfindv32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\whoswatchingme.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wimmun32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\win-bugsfix.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\win32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\win32us.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winactive.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windll32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\window.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows Police Pro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wininetd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wininitx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winlogin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winppr32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winrecon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winservn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winssk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winstart.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winstart001.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wintsk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wkufind.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wnad.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wradmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wrctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsbgate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxas.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxfw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsctool.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wupdater.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wupdt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wyvernworksfirewall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpdeluxe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpf202en.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zatutor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zonalm2601.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zonealarm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~1.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-phk.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsSmartPartner_1.png"><img class="alignnone size-medium wp-image-2869" title="Rogue.Win32.WindowsSmartPartner" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsSmartPartner_1-400x234.png" alt="Rogue.Win32.WindowsSmartPartner" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsSmartPartner_2.png"><img class="alignnone size-medium wp-image-2870" title="Rogue.Win32.WindowsSmartPartner" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsSmartPartner_2-400x293.png" alt="Rogue.Win32.WindowsSmartPartner" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsSmartPartner_3.png"><img class="alignnone size-medium wp-image-2871" title="Rogue.Win32.WindowsSmartPartner" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsSmartPartner_3-400x293.png" alt="Rogue.Win32.WindowsSmartPartner" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsSmartPartner_4.png"><img class="alignnone size-medium wp-image-2872" title="Rogue.Win32.WindowsSmartPartner" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsSmartPartner_4-400x238.png" alt="Rogue.Win32.WindowsSmartPartner" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsSmartPartner_5.png"><img class="alignnone size-medium wp-image-2873" title="Rogue.Win32.WindowsSmartPartner" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsSmartPartner_5-400x253.png" alt="Rogue.Win32.WindowsSmartPartner" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Smart Partner </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSmartPartner" target="_blank">Rogue.Win32.WindowsSmartPartner</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/02/21/windows-smart-partner-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Home Malware Cleaner Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/02/21/home-malware-cleaner-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/02/21/home-malware-cleaner-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 21 Feb 2012 07:30:54 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Home Malware Cleaner]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2860</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Home Malware Cleaner. Emsisoft Anti-Malware detects this malware as Rogue.Win32.HomeMalwareCleaner. Home Malware Cleaner is a rogue scanner application, another variant of SmartAntiMalwareProtection, Antivirus Smart Protection, Malware Protection Center and Internet Security Guard. A rogue application tries to trick you by displaying false positive or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong>Home Malware Cleaner</strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.HomeMalwareCleaner" href="http://www.emsisoft.com/en/malware/?Adware.Win32.HomeMalwareCleaner" target="_blank"><strong>Rogue.Win32.HomeMalwareCleaner</strong></a><strong>.</strong></p>
<p><strong>Home Malware Cleaner </strong><strong></strong>is a rogue scanner application, another variant of <a title="Rogue.Win32.SmartAntiMalwareProtection" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartAntiMalwareProtection" target="_blank"><strong>SmartAntiMalwareProtection</strong></a><strong></strong>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirusSmartProtection"><strong>Antivirus Smart Protection</strong></a>, <a title="Malware Protection Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.MalwareProtectionCenter"><strong>Malware Protection Center</strong></a> and <a title="Rogue.Win32.InternetSecurityGuard" href="http://www.emsisoft.com/en/malware/?Adware.Win32.InternetSecurityGuard" target="_blank"><strong>Internet Security Guard</strong></a>. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\5c678c\</li>
<li>%AllUsersProfile%\Application Data\5c678c\BackUp\</li>
<li>%AllUsersProfile%\Application Data\5c678c\HMCSys\</li>
<li>%AllUsersProfile%\Application Data\5c678c\Quarantine Items\</li>
<li>%AllUsersProfile%\Application Data\5c678c\51.mof</li>
<li>%AllUsersProfile%\Application Data\5c678c\HM5c6_8010.exe</li>
<li>%AllUsersProfile%\Application Data\5c678c\HMC.ico</li>
<li>%AllUsersProfile%\Application Data\5c678c\mozcrt19.dll</li>
<li>%AllUsersProfile%\Application Data\5c678c\sqlite3.dll</li>
<li>%AllUsersProfile%\Application Data\HMEMLLCC\</li>
<li>%AllUsersProfile%\Application Data\HMEMLLCC\HMFLAAC.cfg</li>
<li>%AppData%\Home Malware Cleaner\</li>
<li>%AppData%\Home Malware Cleaner\cookies.sqlite</li>
<li>%AppData%\Home Malware Cleaner\Instructions.ini</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\Home Malware Cleaner.lnk</li>
<li>%UserProfile%\Desktop\Home Malware Cleaner.lnk</li>
<li>%Temp%\scandsk211d_8010.exe</li>
<li>%UserProfile%\Recent\energy.sys</li>
<li>%UserProfile%\Start Menu\Home Malware Cleaner.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Home Malware Cleaner.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\Classes\HM5c6_8010.DocHostUIHandler<br />
Default = Implements DocHostUIHandler<br />
Clsid  = {3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\Classes\clsid\{3F2BBC05-40DF-11D2-9455-00104BC936FF}<br />
Default = Implements DocHostUIHandler<br />
LocalServer32  = %AllUsersProfile%\Application Data\5c678c\HM5c6_8010.exe<br />
ProgID  = HM5c6_8010.DocHostUIHandler</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cl.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frmwrk32.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\homeav2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init32.exe \<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MalwareRemoval.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ozn695m5.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsAuxs.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsGui.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsSvc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsTray.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PC_Antispyware2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfndr.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PerAvir.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protector.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qh.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quick Heal.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\QuickHealCleaner.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Save.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveArmor.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveDefense.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveKeep.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secure Veteran.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\secureveteran.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Security Center.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SecurityFighter.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\securitysoldier.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smart.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartprotector.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smrtdefp.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftSafeness.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spywarexpguard.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrustWarrior.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\W3asbas.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windll32.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows Police Pro.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpdeluxe.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~1.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~2.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\3</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures = no<br />
RunInvalidSignatures = 01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\<br />
Home Malware Cleaner = “%AllUsersProfile%\Application Data\5c678c\HM5c6_8010.exe” /s /d</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\RunOnce\<br />
SAMP = “%Temp%\scandsk211d_8010.exe” /cs:0</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.HomeMalwareCleaner_1.png"><img class="alignnone size-medium wp-image-2861" title="Rogue.Win32.HomeMalwareCleaner" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.HomeMalwareCleaner_1-400x201.png" alt="Rogue.Win32.HomeMalwareCleaner" width="400" height="201" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.HomeMalwareCleaner_2.png"><img class="alignnone size-medium wp-image-2862" title="Rogue.Win32.HomeMalwareCleaner" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.HomeMalwareCleaner_2-400x292.png" alt="Rogue.Win32.HomeMalwareCleaner" width="400" height="292" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.HomeMalwareCleaner_3.png"><img class="alignnone size-medium wp-image-2863" title="Rogue.Win32.HomeMalwareCleaner" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.HomeMalwareCleaner_3-400x292.png" alt="Rogue.Win32.HomeMalwareCleaner" width="400" height="292" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.HomeMalwareCleaner_4.png"><img class="alignnone size-medium wp-image-2864" title="Rogue.Win32.HomeMalwareCleaner" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.HomeMalwareCleaner_4-400x197.png" alt="Rogue.Win32.HomeMalwareCleaner" width="400" height="197" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><strong></strong><span style="color: #ff0000;"><strong>U2FD-S2LA-H4KA-UEPB</strong></span></pre>
<p><strong>How to remove the infection of Home Malware Cleaner </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HomeMalwareCleaner" target="_blank">Rogue.Win32.HomeMalwareCleaner</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Smart Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/02/15/smart-anti-malware-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Smart Anti-Malware Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/03/advanced-antispyware-solution-rogue-removal-instructions/" rel="bookmark" class="crp_title">Advanced Antispyware Solution Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/02/21/home-malware-cleaner-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Smart Warden Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/02/20/windows-smart-warden-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/02/20/windows-smart-warden-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 20 Feb 2012 09:35:51 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Smart Warden]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2851</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Smart Warden. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsSmartWarden. Windows Smart Warden is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<div>
<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Smart Warden</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsSmartWarden" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSmartWarden" target="_blank"><strong>Rogue.Win32.WindowsSmartWarden</strong></a><strong>.</strong></p>
<p><strong>Windows Smart Warden </strong><strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-wbq.exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Smart Warden.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Smart Warden.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AluSchedulerSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\amon9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\anti-trojan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirus.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ants.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\apimonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aplica32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\apvxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\arr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashAvast.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashBug.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashChest.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashCnsnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashLogV.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashMaiSv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashPopWz.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashQuick.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashServ.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSimp2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSimpl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSkPcc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSkPck.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashUpd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashWebSv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswChLic.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswRegSvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswRunDll.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswUpdSv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atcon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atro55en.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atupdater.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\au.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\auto-protect.nav80try.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\autodown.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\autotrace.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avadmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avcenter.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avciman.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconfig.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconsol.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ave32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgchk.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcsrvx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgdumpx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgemc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgiproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnsx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrsx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgscanx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgserv9.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgsrmax.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgtray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgwdsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkpop.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkservice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkwctl9.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avltmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avmailc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avmcdlg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avnotify.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpcc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpdos32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avptc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avsched32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avsynmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avupgsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVWEBGRD.EXE\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwin95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwinnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwsc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupsrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxmonitor9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxmonitornt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxquar.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\b.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\backweb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bargains.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvcl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvwiz.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDInProcPatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdmcon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDMsnScan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDSurvey.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bd_professional.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\beagle.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\belt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bidef.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bidserver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bipcp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bipcpevalsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bisp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blackd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blackice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blink.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blss.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bootconf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bootwarn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\borg2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brasil.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bs120.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bspatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bundle.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bvt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\c.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cavscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccevtmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccpxysvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccSvcHst.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cdp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfgwiz.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfiadmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfiaudit.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfinet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfinet32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfpconfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfplogvw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfpupdat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\claw95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\claw95cf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\clean.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleaner.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleaner3.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleanIELow.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleanpc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\click.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmdagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmesys.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmgrdian.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmon016.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\connectionmonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\control\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpf9x206.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpfnt206.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\crashrep.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssconfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssupdat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssurf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cwnb181.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cwntdwmo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\d.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\datemanager.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dcomx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\defalert.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\defscangui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\defwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\deloeminfs.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\deputy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dllcache.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dllreg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\doors.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpfsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpps2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\driverctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\drwatson.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\drweb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\drwebupw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dssagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dvp95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dvp95_0.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ecengine.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\efpeadm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\emsw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\esafe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\escanhnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\escanv95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\espwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ethereal.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\etrustcipe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\evpn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\exantivirus-cnet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\exe.avxw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\expert.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\explore.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-agnt95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-prot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-prot95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-stopw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fact.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fameh32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fast.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fch32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fih32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\findviru.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\firewall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fixcfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fixfp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fnrb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fp-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fp-win_trial.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fprot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frmwrk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsaa.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav530stbyb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav530wtbyb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsgk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsm32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsma32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsmb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gator.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbmenu.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbpoll.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\generics.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gmt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\guard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\guarddog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\guardgui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hacktracersetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hbinst.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hbsrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\History.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\homeav2010.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hotactio.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hotpatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\htlog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\htpatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hwpe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hxdl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hxiul.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamstats.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ibmasn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ibmavsp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icload95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icloadnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icsupp95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icsuppnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Identity.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\idle.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iedll.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iedriver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\IEShow.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iface.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ifw2000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\inetlnfo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\infus.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\infwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init32.exe \<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[1].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[2].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[3].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[4].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[5].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\intdel.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\intren.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iomon98.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\istsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\jammer.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\jdbgmrg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\jedi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\JsRcGen.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavlite40eng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavpers40eng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavpf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kazza.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\keenvalue.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-pf-213-en-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-wrl-421-en-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-wrp-421-en-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\killprocesssetup161.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldnetmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldpro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldpromenu.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\licmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lnetinfo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\loader.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\localnet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lockdown.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lockdown2000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lookout.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lordpe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luau.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lucomserver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luinit.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luspt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MalwareRemoval.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mapisvc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcmnhdlr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcmscsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcnasvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\McSACore.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcshell.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcshield.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcsysmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mctool.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcvsrte.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcvsshld.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\md.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfw2en.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfweng3.02d30.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgavrtcl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgavrte.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mghtml.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\minilog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmod.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\monitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\moolive.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpfagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpfservice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MPFSrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpftray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mrflux.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mrt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msa.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msbb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msblast.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscache.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msccn32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscman.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msdm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msdos.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msiexec16.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mslaugh.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmgt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmsgri32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mssmmc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mssys.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msvxd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mu0311ad.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\n32scanw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navap.navapsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navapsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navapw32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navdx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navlu32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navstub.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navw32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navwnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nc2000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ncinst4.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ndd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\neomonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\neowatchlog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netarmor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netinfo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netscanpro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netspyhunter-1.2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netutils.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nisserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nisum.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\normist.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\norton_internet_secu_3.0_407.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\notstart.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npf40_tw_98_nt_me_2k.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npfmessenger.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nprotect.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npscheck.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npssvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nsched32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nssys32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nstask32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nsupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntrtscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntvdm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntxconfig.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nupgrade.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvarch16.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvc95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvsvc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwinst4.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwservice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwtool16.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAcat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAhlp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAReg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\oasrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\oaui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\oaview.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ODSW.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ollydbg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\onsrvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\optimize.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ostronet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\otfix.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpostinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpostproinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ozn695m5.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\padmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\panixk.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\patch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavcl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PavFnSvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavprsrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavsched.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavsrv51.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pccwin98.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcfwallicon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcip10117_0.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsAuxs.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsGui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PC_Antispyware2010.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfndr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PerAvir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\periscope.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\persfw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\perswf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pf2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pfwadmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pgmonitr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pingscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pop3trap.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\poproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\popscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\portdetective.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\portmonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ppinupdt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pptbc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ppvstop.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\prizesurfer.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\prmt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\prmvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\procdump.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\processmonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexplorerv1.0.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\programauditor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\proport.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protector.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANCU.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANHost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANToManager.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PsCtrls.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PsImSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PskSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pspf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSUNMain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\purge.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qconsole.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qh.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qserver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quick Heal.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\QuickHealCleaner.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rapapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav7.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav7win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav8win32eng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rcsync.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\realmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\reged.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe\<br />
Debugger = C:\Documents and Settings\Administrator\Application Data\Inspector-pwe.exe reg</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedt32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rescue.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rescue32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rrguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rscdwld.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rshell.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rtvscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rtvscn95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rulaunch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeweb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sahagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Save.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveArmor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveDefense.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveKeep.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\savenow.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sbserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scam32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scanpm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scrscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secure Veteran.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\secureveteran.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Security Center.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SecurityFighter.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\securitysoldier.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\serv95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\setloadorder.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\setupvameeval.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup_flowprotector_us.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sgssfw32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sh.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\shellspyinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\shield.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\shn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\showbehind.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\signcheck.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smart.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartprotector.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smrtdefp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sms.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smss32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\snetcfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\soap.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sofi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftSafeness.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sperm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sphinx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoler.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolcv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolsv32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spywarexpguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spyxx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\srexe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\srng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ss3edit.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssgrate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssg_4104.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\st2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\start.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\stcloader.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\supftrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\support.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\supporter5.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchostc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchosts.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svshost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweep95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweepnet.sweepsrv.sys.swnetsup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\symproxysvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\symtray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\system.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\system32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sysupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe\<br />
Debugger = C:\Documents and Settings\Administrator\Application Data\Inspector-pwe.exe task</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\taumon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tca.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tcm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds-3.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds2-98.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds2-nt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\teekids.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tfak.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tfak5.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tgbob.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\titanin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\titaninxp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TPSrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trickler.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trjscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trjsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trojantrap3.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrustWarrior.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsadbot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tvmd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tvtmd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\undoboot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\updat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\upgrad.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\utpost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbcmserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbcons.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbust.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbwin9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbwinntw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vcsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vet32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vet95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vettray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vfsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vir-help.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\virusmdpersonalfirewall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthAux.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthLic.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthUpd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vnlan300.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vnpc3000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpc42.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpfw30s.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vptray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vscan40.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vscenu6.02d30.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsched.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsecomr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vshwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsisetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsstat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswin9xe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswinntse.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswinperse.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\w32dsm89.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\W3asbas.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\w9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\watchdog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\webdav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\WebProxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\webscanx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\webtrap.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wfindv32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\whoswatchingme.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wimmun32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\win-bugsfix.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\win32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\win32us.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winactive.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windll32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\window.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows Police Pro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wininetd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wininitx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winlogin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winppr32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winrecon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winservn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winssk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winstart.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winstart001.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wintsk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wkufind.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wnad.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wradmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wrctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsbgate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxas.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxfw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsctool.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wupdater.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wupdt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wyvernworksfirewall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpdeluxe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpf202en.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zatutor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zonalm2601.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zonealarm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~1.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-wbq.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsSmartWarden_1.png"><img class="alignnone size-medium wp-image-2852" title="Rogue.Win32.WindowsSmartWarden" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsSmartWarden_1-400x234.png" alt="Rogue.Win32.WindowsSmartWarden" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsSmartWarden_2.png"><img class="alignnone size-medium wp-image-2853" title="Rogue.Win32.WindowsSmartWarden" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsSmartWarden_2-400x293.png" alt="Rogue.Win32.WindowsSmartWarden" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsSmartWarden_3.png"><img class="alignnone size-medium wp-image-2854" title="Rogue.Win32.WindowsSmartWarden" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsSmartWarden_3-400x293.png" alt="Rogue.Win32.WindowsSmartWarden" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsSmartWarden_4.png"><img class="alignnone size-medium wp-image-2855" title="Rogue.Win32.WindowsSmartWarden" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsSmartWarden_4-400x238.png" alt="Rogue.Win32.WindowsSmartWarden" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsSmartWarden_5.png"><img class="alignnone size-medium wp-image-2856" title="Rogue.Win32.WindowsSmartWarden" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsSmartWarden_5-400x253.png" alt="Rogue.Win32.WindowsSmartWarden" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Smart Warden </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsSmartWarden" target="_blank">Rogue.Win32.WindowsSmartWarden</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
</div>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/02/20/windows-smart-warden-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Functionality Checker Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/02/17/windows-functionality-checker-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/02/17/windows-functionality-checker-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 17 Feb 2012 14:57:05 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Functionality Checker]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2841</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Functionality Checker. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsFunctionalityChecker. Windows Functionality Checker is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Functionality Checker</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsFunctionalityChecker" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFunctionalityChecker" target="_blank"><strong>Rogue.Win32.WindowsFunctionalityChecker</strong></a><strong>.</strong></p>
<p><strong>Windows Functionality Checker </strong><strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Protector-nbi.exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Functionality Checker.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Functionality Checker.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AluSchedulerSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\amon9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\anti-trojan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirus.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ants.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\apimonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aplica32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\apvxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\arr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashAvast.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashBug.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashChest.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashCnsnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashLogV.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashMaiSv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashPopWz.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashQuick.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashServ.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSimp2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSimpl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSkPcc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSkPck.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashUpd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashWebSv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswChLic.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswRegSvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswRunDll.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswUpdSv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atcon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atro55en.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atupdater.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\au.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\auto-protect.nav80try.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\autodown.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\autotrace.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avadmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avcenter.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avciman.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconfig.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconsol.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ave32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgchk.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcsrvx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgdumpx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgemc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgiproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnsx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrsx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgscanx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgserv9.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgsrmax.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgtray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgwdsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkpop.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkservice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkwctl9.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avltmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avmailc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avmcdlg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avnotify.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpcc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpdos32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avptc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avsched32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avsynmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avupgsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVWEBGRD.EXE\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwin95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwinnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwsc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupsrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxmonitor9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxmonitornt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxquar.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\b.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\backweb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bargains.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvcl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvwiz.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDInProcPatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdmcon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDMsnScan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDSurvey.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bd_professional.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\beagle.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\belt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bidef.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bidserver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bipcp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bipcpevalsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bisp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blackd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blackice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blink.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blss.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bootconf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bootwarn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\borg2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brasil.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bs120.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bspatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bundle.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bvt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\c.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cavscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccevtmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccpxysvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccSvcHst.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cdp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfgwiz.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfiadmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfiaudit.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfinet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfinet32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfpconfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfplogvw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfpupdat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\claw95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\claw95cf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\clean.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleaner.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleaner3.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleanIELow.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleanpc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\click.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmdagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmesys.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmgrdian.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmon016.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\connectionmonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\control\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpf9x206.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpfnt206.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\crashrep.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssconfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssupdat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssurf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cwnb181.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cwntdwmo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\d.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\datemanager.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dcomx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\defalert.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\defscangui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\defwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\deloeminfs.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\deputy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dllcache.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dllreg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\doors.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpfsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpps2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\driverctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\drwatson.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\drweb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\drwebupw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dssagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dvp95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dvp95_0.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ecengine.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\efpeadm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\emsw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\esafe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\escanhnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\escanv95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\espwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ethereal.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\etrustcipe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\evpn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\exantivirus-cnet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\exe.avxw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\expert.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\explore.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-agnt95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-prot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-prot95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-stopw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fact.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fameh32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fast.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fch32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fih32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\findviru.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\firewall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fixcfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fixfp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fnrb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fp-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fp-win_trial.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fprot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frmwrk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsaa.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav530stbyb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav530wtbyb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsgk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsm32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsma32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsmb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gator.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbmenu.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbpoll.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\generics.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gmt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\guard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\guarddog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\guardgui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hacktracersetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hbinst.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hbsrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\History.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\homeav2010.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hotactio.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hotpatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\htlog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\htpatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hwpe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hxdl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hxiul.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamstats.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ibmasn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ibmavsp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icload95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icloadnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icsupp95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icsuppnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Identity.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\idle.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iedll.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iedriver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\IEShow.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iface.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ifw2000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\inetlnfo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\infus.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\infwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init32.exe \<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[1].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[2].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[3].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[4].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[5].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\intdel.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\intren.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iomon98.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\istsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\jammer.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\jdbgmrg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\jedi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\JsRcGen.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavlite40eng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavpers40eng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavpf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kazza.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\keenvalue.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-pf-213-en-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-wrl-421-en-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-wrp-421-en-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\killprocesssetup161.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldnetmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldpro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldpromenu.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\licmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lnetinfo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\loader.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\localnet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lockdown.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lockdown2000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lookout.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lordpe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luau.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lucomserver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luinit.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luspt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MalwareRemoval.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mapisvc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcmnhdlr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcmscsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcnasvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\McSACore.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcshell.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcshield.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcsysmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mctool.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcvsrte.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcvsshld.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\md.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfw2en.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfweng3.02d30.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgavrtcl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgavrte.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mghtml.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\minilog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmod.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\monitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\moolive.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpfagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpfservice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MPFSrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpftray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mrflux.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mrt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msa.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msbb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msblast.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscache.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msccn32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscman.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msdm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msdos.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msiexec16.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mslaugh.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmgt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmsgri32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mssmmc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mssys.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msvxd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mu0311ad.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\n32scanw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navap.navapsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navapsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navapw32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navdx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navlu32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navstub.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navw32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navwnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nc2000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ncinst4.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ndd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\neomonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\neowatchlog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netarmor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netinfo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netscanpro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netspyhunter-1.2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netutils.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nisserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nisum.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\normist.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\norton_internet_secu_3.0_407.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\notstart.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npf40_tw_98_nt_me_2k.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npfmessenger.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nprotect.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npscheck.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npssvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nsched32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nssys32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nstask32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nsupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntrtscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntvdm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntxconfig.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nupgrade.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvarch16.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvc95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvsvc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwinst4.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwservice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwtool16.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAcat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAhlp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAReg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\oasrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\oaui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\oaview.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ODSW.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ollydbg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\onsrvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\optimize.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ostronet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\otfix.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpostinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpostproinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ozn695m5.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\padmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\panixk.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\patch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavcl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PavFnSvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavprsrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavsched.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavsrv51.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pccwin98.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcfwallicon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcip10117_0.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsAuxs.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsGui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PC_Antispyware2010.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfndr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PerAvir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\periscope.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\persfw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\perswf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pf2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pfwadmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pgmonitr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pingscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pop3trap.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\poproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\popscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\portdetective.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\portmonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ppinupdt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pptbc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ppvstop.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\prizesurfer.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\prmt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\prmvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\procdump.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\processmonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexplorerv1.0.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\programauditor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\proport.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protector.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANCU.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANHost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANToManager.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PsCtrls.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PsImSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PskSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pspf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSUNMain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\purge.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qconsole.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qh.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qserver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quick Heal.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\QuickHealCleaner.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rapapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav7.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav7win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav8win32eng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rcsync.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\realmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\reged.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe\<br />
Debugger = C:\Documents and Settings\Administrator\Application Data\Inspector-pwe.exe reg</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedt32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rescue.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rescue32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rrguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rscdwld.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rshell.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rtvscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rtvscn95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rulaunch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeweb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sahagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Save.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveArmor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveDefense.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveKeep.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\savenow.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sbserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scam32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scanpm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scrscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secure Veteran.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\secureveteran.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Security Center.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SecurityFighter.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\securitysoldier.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\serv95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\setloadorder.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\setupvameeval.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup_flowprotector_us.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sgssfw32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sh.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\shellspyinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\shield.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\shn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\showbehind.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\signcheck.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smart.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartprotector.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smrtdefp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sms.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smss32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\snetcfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\soap.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sofi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftSafeness.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sperm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sphinx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoler.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolcv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolsv32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spywarexpguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spyxx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\srexe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\srng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ss3edit.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssgrate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssg_4104.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\st2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\start.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\stcloader.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\supftrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\support.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\supporter5.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchostc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchosts.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svshost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweep95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweepnet.sweepsrv.sys.swnetsup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\symproxysvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\symtray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\system.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\system32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sysupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe\<br />
Debugger = C:\Documents and Settings\Administrator\Application Data\Inspector-pwe.exe task</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\taumon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tca.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tcm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds-3.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds2-98.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds2-nt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\teekids.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tfak.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tfak5.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tgbob.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\titanin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\titaninxp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TPSrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trickler.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trjscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trjsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trojantrap3.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrustWarrior.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsadbot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tvmd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tvtmd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\undoboot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\updat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\upgrad.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\utpost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbcmserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbcons.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbust.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbwin9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbwinntw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vcsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vet32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vet95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vettray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vfsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vir-help.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\virusmdpersonalfirewall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthAux.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthLic.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthUpd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vnlan300.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vnpc3000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpc42.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpfw30s.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vptray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vscan40.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vscenu6.02d30.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsched.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsecomr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vshwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsisetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsstat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswin9xe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswinntse.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswinperse.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\w32dsm89.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\W3asbas.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\w9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\watchdog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\webdav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\WebProxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\webscanx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\webtrap.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wfindv32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\whoswatchingme.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wimmun32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\win-bugsfix.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\win32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\win32us.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winactive.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windll32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\window.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows Police Pro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wininetd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wininitx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winlogin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winppr32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winrecon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winservn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winssk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winstart.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winstart001.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wintsk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wkufind.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wnad.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wradmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wrctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsbgate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxas.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxfw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsctool.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wupdater.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wupdt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wyvernworksfirewall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpdeluxe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpf202en.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zatutor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zonalm2601.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zonealarm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~1.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Protector-nbi.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsFunctionalityChecker_1.png"><img class="alignnone size-medium wp-image-2842" title="Rogue.Win32.WindowsFunctionalityChecker" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsFunctionalityChecker_1-400x234.png" alt="Rogue.Win32.WindowsFunctionalityChecker" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsFunctionalityChecker_2.png"><img class="alignnone size-medium wp-image-2843" title="Rogue.Win32.WindowsFunctionalityChecker" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsFunctionalityChecker_2-400x293.png" alt="Rogue.Win32.WindowsFunctionalityChecker" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsFunctionalityChecker_3.png"><img class="alignnone size-medium wp-image-2844" title="Rogue.Win32.WindowsFunctionalityChecker" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsFunctionalityChecker_3-400x293.png" alt="Rogue.Win32.WindowsFunctionalityChecker" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsFunctionalityChecker_4.png"><img class="alignnone size-medium wp-image-2845" title="Rogue.Win32.WindowsFunctionalityChecker" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsFunctionalityChecker_4-400x238.png" alt="Rogue.Win32.WindowsFunctionalityChecker" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsFunctionalityChecker_5.png"><img class="alignnone size-medium wp-image-2846" title="Rogue.Win32.WindowsFunctionalityChecker" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsFunctionalityChecker_5-400x253.png" alt="Rogue.Win32.WindowsFunctionalityChecker" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Functionality Checker </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsFunctionalityChecker" target="_blank">Rogue.Win32.WindowsFunctionalityChecker</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/02/17/windows-functionality-checker-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Protection Master Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/02/15/windows-protection-master-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/02/15/windows-protection-master-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 15 Feb 2012 14:09:07 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Protection Master]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2833</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Windows Protection Master. Emsisoft Anti-Malware detects this malware as Rogue.Win32.WindowsProtectionMaster. Windows Protection Master is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Windows Protection Master</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.WindowsProtectionMaster" href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionMaster" target="_blank"><strong>Rogue.Win32.WindowsProtectionMaster</strong></a><strong>.</strong></p>
<p><strong>Windows Protection Master </strong><strong></strong>is a rogue scanner application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Inspector-pwe.exe</li>
<li>%AppData%\result.db</li>
<li>%UserProfile%\Desktop\Windows Protection Master.lnk</li>
<li>%AllUsersProfile%\Start Menu\Programs\Windows Protection Master.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\About.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ad-Aware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alevir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AluSchedulerSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\amon9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\anti-trojan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirus.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ants.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\apimonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aplica32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\apvxdwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\arr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashAvast.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashBug.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashChest.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashCnsnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashLogV.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashMaiSv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashPopWz.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashQuick.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashServ.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSimp2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSimpl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSkPcc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSkPck.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashUpd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashWebSv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswChLic.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswRegSvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswRunDll.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswUpdSv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atcon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atro55en.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atupdater.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\atwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\au.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\aupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\auto-protect.nav80try.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\autodown.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\autotrace.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avadmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avcenter.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avciman.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconfig.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconsol.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ave32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgchk.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcsrvx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgdumpx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgemc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgiproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnsx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrsx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgscanx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgserv9.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgsrmax.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgtray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgwdsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkpop.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkservice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avkwctl9.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avltmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avmailc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avmcdlg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avnotify.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpcc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpdos32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avptc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avsched32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avsynmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avupgsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVWEBGRD.EXE\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwin95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwinnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwsc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwupsrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxmonitor9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxmonitornt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxquar.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\b.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\backweb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bargains.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvcl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvwiz.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDInProcPatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdmcon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDMsnScan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\BDSurvey.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bd_professional.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\beagle.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\belt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bidef.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bidserver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bipcp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bipcpevalsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bisp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blackd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blackice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blink.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\blss.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bootconf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bootwarn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\borg2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brasil.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bs120.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bspatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bundle.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\bvt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\c.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cavscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccevtmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccpxysvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccSvcHst.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cdp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfgwiz.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfiadmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfiaudit.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfinet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfinet32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfpconfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfplogvw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfpupdat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\claw95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\claw95cf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\clean.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleaner.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleaner3.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleanIELow.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cleanpc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\click.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmdagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmesys.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmgrdian.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmon016.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\connectionmonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\control\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpf9x206.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cpfnt206.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\crashrep.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssconfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssupdat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cssurf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cwnb181.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\cwntdwmo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\d.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\datemanager.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dcomx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\defalert.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\defscangui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\defwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\deloeminfs.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\deputy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dllcache.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dllreg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\doors.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpfsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dpps2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\driverctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\drwatson.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\drweb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\drwebupw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dssagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dvp95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dvp95_0.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ecengine.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\efpeadm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\emsw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\esafe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\escanhnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\escanv95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\espwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ethereal.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\etrustcipe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\evpn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\exantivirus-cnet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\exe.avxw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\expert.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\explore.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-agnt95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-prot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-prot95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\f-stopw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fact.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fameh32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fast.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fch32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fih32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\findviru.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\firewall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fixcfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fixfp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fnrb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fp-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fp-win_trial.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fprot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frmwrk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsaa.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav530stbyb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav530wtbyb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsgk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsm32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsma32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsmb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gator.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbmenu.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbpoll.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\generics.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gmt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\guard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\guarddog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\guardgui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hacktracersetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hbinst.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hbsrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\History.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\homeav2010.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hotactio.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hotpatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\htlog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\htpatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hwpe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hxdl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\hxiul.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iamstats.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ibmasn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ibmavsp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icload95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icloadnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icsupp95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\icsuppnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Identity.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\idle.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iedll.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iedriver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\IEShow.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iface.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ifw2000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\inetlnfo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\infus.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\infwin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init32.exe \<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[1].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[2].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[3].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[4].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\install[5].exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\intdel.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\intren.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\iomon98.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\istsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\jammer.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\jdbgmrg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\jedi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\JsRcGen.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavlite40eng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavpers40eng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kavpf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kazza.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\keenvalue.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-pf-213-en-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-wrl-421-en-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\kerio-wrp-421-en-win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\killprocesssetup161.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldnetmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldpro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldpromenu.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ldscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\licmgr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lnetinfo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\loader.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\localnet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lockdown.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lockdown2000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lookout.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lordpe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luau.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\lucomserver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luinit.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\luspt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MalwareRemoval.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mapisvc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcmnhdlr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcmscsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcnasvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\McSACore.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcshell.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcshield.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcsysmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mctool.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcvsrte.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcvsshld.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\md.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfw2en.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mfweng3.02d30.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgavrtcl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgavrte.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mghtml.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mgui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\minilog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmod.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\monitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\moolive.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mostat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpfagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpfservice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MPFSrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpftray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mrflux.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mrt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msa.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msbb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msblast.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscache.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msccn32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscman.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msdm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msdos.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msiexec16.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mslaugh.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmgt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmsgri32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mssmmc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mssys.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\msvxd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mu0311ad.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\mwatch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\n32scanw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navap.navapsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navapsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navapw32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navdx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navlu32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navstub.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navw32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\navwnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nc2000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ncinst4.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ndd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\neomonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\neowatchlog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netarmor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netd32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netinfo.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netscanpro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netspyhunter-1.2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\netutils.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nisserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nisum.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\normist.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\norton_internet_secu_3.0_407.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\notstart.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npf40_tw_98_nt_me_2k.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npfmessenger.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nprotect.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npscheck.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\npssvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nsched32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nssys32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nstask32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nsupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntrtscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntvdm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntxconfig.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nupgrade.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvarch16.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvc95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nvsvc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwinst4.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwservice.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\nwtool16.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAcat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAhlp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\OAReg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\oasrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\oaui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\oaview.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ODSW.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ollydbg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\onsrvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\optimize.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ostronet.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\otfix.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpostinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpostproinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ozn695m5.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\padmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\panixk.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\patch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavcl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PavFnSvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavprsrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavsched.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavsrv51.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pccwin98.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcfwallicon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcip10117_0.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsAuxs.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsGui.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsTray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PC_Antispyware2010.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfndr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PerAvir.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\periscope.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\persfw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\perswf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pf2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pfwadmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pgmonitr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pingscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\platin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pop3trap.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\poproxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\popscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\portdetective.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\portmonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ppinupdt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pptbc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ppvstop.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\prizesurfer.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\prmt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\prmvr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\procdump.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\processmonitor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexplorerv1.0.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\programauditor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\proport.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protector.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANCU.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANHost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSANToManager.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PsCtrls.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PsImSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PskSvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pspf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSUNMain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\purge.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qconsole.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qh.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qserver.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quick Heal.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\QuickHealCleaner.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rapapp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav7.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav7win.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rav8win32eng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rb32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rcsync.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\realmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\reged.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe\<br />
Debugger = C:\Documents and Settings\Administrator\Application Data\Inspector-pwe.exe reg</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedt32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rescue.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rescue32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rrguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rscdwld.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rshell.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rtvscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rtvscn95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rulaunch.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeweb.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sahagent.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Save.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveArmor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveDefense.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveKeep.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\savenow.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sbserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scam32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scanpm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\scrscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secure Veteran.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\secureveteran.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Security Center.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SecurityFighter.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\securitysoldier.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\serv95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\setloadorder.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\setupvameeval.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup_flowprotector_us.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sgssfw32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sh.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\shellspyinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\shield.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\shn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\showbehind.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\signcheck.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smart.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartprotector.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smrtdefp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sms.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smss32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\snetcfg.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\soap.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sofi.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftSafeness.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sperm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spf.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sphinx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoler.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolcv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolsv32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spywarexpguard.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spyxx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\srexe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\srng.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ss3edit.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssgrate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssg_4104.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\st2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\start.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\stcloader.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\supftrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\support.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\supporter5.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchostc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchosts.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\svshost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweep95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweepnet.sweepsrv.sys.swnetsup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcsvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\symproxysvc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\symtray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\system.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\system32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\sysupd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe\<br />
Debugger = C:\Documents and Settings\Administrator\Application Data\Inspector-pwe.exe task</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\taumon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tca.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tcm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds-3.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds2-98.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tds2-nt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\teekids.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tfak.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tfak5.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tgbob.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\titanin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\titaninxp.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TPSrv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trickler.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trjscan.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trjsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\trojantrap3.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrustWarrior.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsadbot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tvmd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tvtmd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\undoboot.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\updat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\upgrad.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\utpost.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbcmserv.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbcons.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbust.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbwin9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbwinntw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vcsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vet32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vet95.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vettray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vfsetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vir-help.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\virusmdpersonalfirewall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthAux.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthLic.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\VisthUpd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vnlan300.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vnpc3000.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpc32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpc42.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vpfw30s.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vptray.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vscan40.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vscenu6.02d30.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsched.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsecomr.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vshwin32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsisetup.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsmon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsstat.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswin9xe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswinntse.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\vswinperse.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\w32dsm89.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\W3asbas.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\w9x.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\watchdog.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\webdav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\WebProxy.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\webscanx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\webtrap.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wfindv32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\whoswatchingme.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wimmun32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\win-bugsfix.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\win32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\win32us.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winactive.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windll32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\window.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows Police Pro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wininetd.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wininitx.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winlogin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winmain.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winppr32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winrecon.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winservn.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winssk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winstart.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winstart001.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wintsk32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winupdate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wkufind.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wnad.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wnt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wradmin.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wrctrl.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsbgate.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxas.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxav.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscfxfw.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsctool.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wupdater.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wupdt.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\wyvernworksfirewall.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpdeluxe.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpf202en.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapro.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zatutor.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zonalm2601.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\zonealarm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpm.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~1.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~2.exe\<br />
Debugger = svchost.exe</li>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
Inspector = %AppData%\Inspector-pwe.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsProtectionMaster_1.png"><img class="alignnone size-medium wp-image-2834" title="Rogue.Win32.WindowsProtectionMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsProtectionMaster_1-400x234.png" alt="Rogue.Win32.WindowsProtectionMaster" width="400" height="234" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsProtectionMaster_2.png"><img class="alignnone size-medium wp-image-2835" title="Rogue.Win32.WindowsProtectionMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsProtectionMaster_2-400x293.png" alt="Rogue.Win32.WindowsProtectionMaster" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsProtectionMaster_3.png"><img class="alignnone size-medium wp-image-2836" title="Rogue.Win32.WindowsProtectionMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsProtectionMaster_3-400x293.png" alt="Rogue.Win32.WindowsProtectionMaster" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsProtectionMaster_4.png"><img class="alignnone size-medium wp-image-2837" title="Rogue.Win32.WindowsProtectionMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsProtectionMaster_4-400x238.png" alt="Rogue.Win32.WindowsProtectionMaster" width="400" height="238" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsProtectionMaster_5.png"><img class="alignnone size-medium wp-image-2838" title="Rogue.Win32.WindowsProtectionMaster" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.WindowsProtectionMaster_5-400x253.png" alt="Rogue.Win32.WindowsProtectionMaster" width="400" height="253" /></a></p>
<p><strong>How to remove the infection of Windows Protection Master </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsProtectionMaster" target="_blank">Rogue.Win32.WindowsProtectionMaster</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/06/windows-malware-sleuth-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Malware Sleuth Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/20/windows-software-keeper-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Keeper Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/03/26/windows-software-saver-rogue-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Saver Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/02/15/windows-protection-master-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Smart Anti-Malware Protection Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/02/15/smart-anti-malware-protection-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/02/15/smart-anti-malware-protection-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 15 Feb 2012 13:26:13 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Smart Anti-Malware Protection]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2825</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Smart Anti-Malware Protection. Emsisoft Anti-Malware detects this malware as Rogue.Win32.SmartAntiMalwareProtection. Smart Anti-Malware Protection is a rogue scanner application, another variant of Antivirus Smart Protection, Malware Protection Center and Internet Security Guard. A rogue application tries to trick you by displaying false positive or misleading [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong><strong>Smart Anti-Malware Protection</strong></strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.SmartAntiMalwareProtection" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartAntiMalwareProtection" target="_blank"><strong>Rogue.Win32.SmartAntiMalwareProtection</strong></a><strong>.</strong></p>
<p><strong>Smart Anti-Malware Protection </strong><strong></strong>is a rogue scanner application, another variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirusSmartProtection"><strong>Antivirus Smart Protection</strong></a>, <a title="Malware Protection Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.MalwareProtectionCenter"><strong>Malware Protection Center</strong></a> and <a title="Rogue.Win32.InternetSecurityGuard" href="http://www.emsisoft.com/en/malware/?Adware.Win32.InternetSecurityGuard" target="_blank"><strong>Internet Security Guard</strong></a>. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\5c678c\</li>
<li>%AllUsersProfile%\Application Data\5c678c\BackUp\</li>
<li>%AllUsersProfile%\Application Data\5c678c\Quarantine Items\</li>
<li>%AllUsersProfile%\Application Data\5c678c\SAMPSys\</li>
<li>%AllUsersProfile%\Application Data\5c678c\8826.mof</li>
<li>%AllUsersProfile%\Application Data\5c678c\mozcrt19.dll</li>
<li>%AllUsersProfile%\Application Data\5c678c\SA5c6_8020.exe</li>
<li>%AllUsersProfile%\Application Data\5c678c\SAMP.ico</li>
<li>%AllUsersProfile%\Application Data\5c678c\sqlite3.dll</li>
<li>%AllUsersProfile%\Application Data\SAQCQZXMP\</li>
<li>%AllUsersProfile%\Application Data\SAQCQZXMP\SAVSDEMP.cfg</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\Smart Anti-Malware Protection.lnk</li>
<li>%AppData%\Smart Anti-Malware Protection\</li>
<li>%AppData%\Smart Anti-Malware Protection\cookies.sqlite</li>
<li>%AppData%\Smart Anti-Malware Protection\Instructions.ini</li>
<li>%UserProfile%\Desktop\Smart Anti-Malware Protection.lnk</li>
<li>%UserProfile%\Start Menu\Smart Anti-Malware Protection.lnk</li>
<li>%UserProfile%\Administrator\Start Menu\Programs\Smart Anti-Malware Protection.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\Classes\SA5c6_8020.DocHostUIHandler<br />
Default = Implements DocHostUIHandler<br />
Clsid  = {3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\Classes\clsid\{3F2BBC05-40DF-11D2-9455-00104BC936FF}<br />
Default = Implements DocHostUIHandler<br />
LocalServer32  = %AllUsersProfile%\Application Data\5c678c\SA5c6_8020.exe<br />
ProgID  = SA5c6_8020.DocHostUIHandler</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cl.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frmwrk32.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\homeav2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init32.exe \<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MalwareRemoval.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ozn695m5.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsAuxs.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsGui.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsSvc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsTray.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PC_Antispyware2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfndr.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PerAvir.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protector.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qh.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quick Heal.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\QuickHealCleaner.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Save.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveArmor.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveDefense.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveKeep.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secure Veteran.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\secureveteran.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Security Center.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SecurityFighter.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\securitysoldier.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smart.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartprotector.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smrtdefp.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftSafeness.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spywarexpguard.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrustWarrior.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\W3asbas.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windll32.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows Police Pro.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpdeluxe.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~1.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~2.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\3</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures = no<br />
RunInvalidSignatures = 01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\<br />
Smart Anti-Malware Protection= “%AllUsersProfile%\Application Data\5c678c\SA5c6_8020.exe” /s /d</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\RunOnce\<br />
SAMP = “%Temp%\[installer].exe” /cs:1</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SmartAntiMalwareProtection_1.png"><img class="alignnone size-medium wp-image-2826" title="Rogue.Win32.SmartAntiMalwareProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SmartAntiMalwareProtection_1-400x201.png" alt="Rogue.Win32.SmartAntiMalwareProtection" width="400" height="201" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SmartAntiMalwareProtection_2.png"><img class="alignnone size-medium wp-image-2827" title="Rogue.Win32.SmartAntiMalwareProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SmartAntiMalwareProtection_2-400x292.png" alt="Rogue.Win32.SmartAntiMalwareProtection" width="400" height="292" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SmartAntiMalwareProtection_3.png"><img class="alignnone size-medium wp-image-2828" title="Rogue.Win32.SmartAntiMalwareProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SmartAntiMalwareProtection_3-400x292.png" alt="Rogue.Win32.SmartAntiMalwareProtection" width="400" height="292" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SmartAntiMalwareProtection_4.png"><img class="alignnone size-medium wp-image-2829" title="Rogue.Win32.SmartAntiMalwareProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SmartAntiMalwareProtection_4-400x197.png" alt="Rogue.Win32.SmartAntiMalwareProtection" width="400" height="197" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SmartAntiMalwareProtection_5.png"><img class="alignnone size-medium wp-image-2830" title="Rogue.Win32.SmartAntiMalwareProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SmartAntiMalwareProtection_5-400x303.png" alt="Rogue.Win32.SmartAntiMalwareProtection" width="400" height="303" /></a></p>
<p>To register and uninstall this rogue application, you can try one of the following serial number:</p>
<pre><strong><span style="color: #ff0000;">K7LY-R5GU-SI9D-EVFB</span></strong>
<strong><span style="color: #ff0000;">U2FD-S2LA-H4KA-UEPB</span></strong></pre>
<p><strong>How to remove the infection of Smart Anti-Malware Protection </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartAntiMalwareProtection" target="_blank">Rogue.Win32.SmartAntiMalwareProtection</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Smart Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/02/21/home-malware-cleaner-rogue-removal-instructions/" rel="bookmark" class="crp_title">Home Malware Cleaner Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/03/advanced-antispyware-solution-rogue-removal-instructions/" rel="bookmark" class="crp_title">Advanced Antispyware Solution Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/02/15/smart-anti-malware-protection-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Scanner 2012 Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/02/13/security-scanner-2012-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/02/13/security-scanner-2012-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 13 Feb 2012 04:53:31 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Security Scanner 2012]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2815</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Security Scanner 2012. Emsisoft Anti-Malware detects this malware as Rogue.Win32.SecurityScanner2012. Security Scanner 2012 is a rogue scanner application, another variant of Security Tool or Security Shield. A rogue application tries to trick you by displaying false positive or misleading scan results report, which [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Security Scanner 2012</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.SecurityScanner2012" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecurityScanner2012" target="_blank"><strong>Rogue.Win32.SecurityScanner2012</strong></a><strong>.</strong></p>
<p><strong>Security Scanner 2012 </strong><strong></strong>is a rogue scanner application, another variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecurityTool" target="_blank"><strong>Security Tool</strong></a> or <strong><a href="../2010/12/09/security-shield-adware-removal-instructions/" target="_blank">Security Shield</a></strong>. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%UserProfile%\Desktop\Security Scanner Support.url</li>
<li>%UserProfile%\Desktop\Security Scanner.lnk</li>
<li>%UserProfile%\Desktop\Uninstall Security Scanner.lnk</li>
<li>%UserProfile%\Local Settings\Application Data\mbancdyulk.exe</li>
<li>%UserProfile%\Local Settings\Application Data\%COMPUTERNAME%.cfg</li>
<li>%UserProfile%\Start Menu\Programs\Security Scanner.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Uninstall Security Scanner.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce<br />
mbancdyulk = %UserProfile%\Local Settings\Application Data\mbancdyulk.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SecurityScanner2012_1.png"><img class="alignnone size-medium wp-image-2816" title="Rogue.Win32.SecurityScanner2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SecurityScanner2012_1-400x318.png" alt="Rogue.Win32.SecurityScanner2012" width="400" height="318" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SecurityScanner2012_2.png"><img class="alignnone size-medium wp-image-2817" title="Rogue.Win32.SecurityScanner2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SecurityScanner2012_2-400x366.png" alt="Rogue.Win32.SecurityScanner2012" width="400" height="366" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SecurityScanner2012_3.png"><img class="alignnone size-medium wp-image-2818" title="Rogue.Win32.SecurityScanner2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SecurityScanner2012_3-400x331.png" alt="Rogue.Win32.SecurityScanner2012" width="400" height="331" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SecurityScanner2012_4.png"><img class="alignnone size-medium wp-image-2819" title="Rogue.Win32.SecurityScanner2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SecurityScanner2012_4-400x197.png" alt="Rogue.Win32.SecurityScanner2012" width="400" height="197" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SecurityScanner2012_5.png"><img class="alignnone size-medium wp-image-2820" title="Rogue.Win32.SecurityScanner2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/02/Rogue.Win32.SecurityScanner2012_5-400x247.png" alt="Rogue.Win32.SecurityScanner2012" width="400" height="247" /></a></p>
<p>To register and uninstall this rogue application, you can try one of the following serial number:</p>
<pre><strong><span style="color: #ff0000;">64C665BE-4DE7-423B-A6B6-BC0172B25DF2</span> </strong></pre>
<p><strong>How to remove the infection of Security Scanner 2012 </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecurityScanner2012" target="_blank">Rogue.Win32.SecurityScanner2012</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/23/internet-security-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/03/security-sphere-2012-removal-instructions/" rel="bookmark" class="crp_title">Security Sphere 2012 Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Security 2012 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/06/security-guard-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Guard 2012 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/23/smart-protection-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Smart Protection 2012 Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/02/13/security-scanner-2012-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Antivirus Smart Protection Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 25 Jan 2012 06:47:18 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Antivirus Smart Protection]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2807</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Antivirus Smart Protection. Emsisoft Anti-Malware detects this malware as Rogue.Win32.AntivirusSmartProtection. Antivirus Smart Protection is a rogue scanner application, another variant of Malware Protection Center and Internet Security Guard. A rogue application tries to trick you by displaying false positive or misleading scan results [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Antivirus Smart Protection</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.AntivirusSmartProtection" href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirusSmartProtection" target="_blank"><strong>Rogue.Win32.AntivirusSmartProtection</strong></a><strong>.</strong></p>
<p><strong>Antivirus Smart Protection </strong><strong></strong>is a rogue scanner application, another variant of <a title="Malware Protection Center" href="http://www.emsisoft.com/en/malware/?Adware.Win32.MalwareProtectionCenter"><strong>Malware Protection Center</strong></a> and <a title="Rogue.Win32.InternetSecurityGuard" href="http://www.emsisoft.com/en/malware/?Adware.Win32.InternetSecurityGuard" target="_blank"><strong>Internet Security Guard</strong></a>. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\5c678c\</li>
<li>%AllUsersProfile%\Application Data\5c678c\sqlite3.dll</li>
<li>%AllUsersProfile%\Application Data\5c678c\ASPSys\</li>
<li>%AllUsersProfile%\Application Data\5c678c\BackUp\</li>
<li>%AllUsersProfile%\Application Data\5c678c\Quarantine Items\</li>
<li>%AllUsersProfile%\Application Data\5c678c\582.mof</li>
<li>%AllUsersProfile%\Application Data\5c678c\AS9c5_8046.exe</li>
<li>%AllUsersProfile%\Application Data\5c678c\ASP.ico</li>
<li>%AllUsersProfile%\Application Data\5c678c\mozcrt19.dll</li>
<li>%AllUsersProfile%\Application Data\ASLNP\</li>
<li>%AllUsersProfile%\Application Data\ASLNP\ASUUDJRRJXP.cfg</li>
<li>%AppData%\Antivirus Smart Protection\</li>
<li>%AppData%\Antivirus Smart Protection\cookies.sqlite</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\Antivirus Smart Protection.lnk</li>
<li>%UserProfile%\Desktop\Antivirus Smart Protection.lnk</li>
<li>%Temp%\scandsk211d_8046.exe</li>
<li>%UserProfile%\Start Menu\Antivirus Smart Protection.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Antivirus Smart Protection.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\Classes\AS9c5_8046.DocHostUIHandler<br />
Default = Implements DocHostUIHandler<br />
Clsid  = {3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\Classes\clsid\{3F2BBC05-40DF-11D2-9455-00104BC936FF}<br />
Default = Implements DocHostUIHandler<br />
LocalServer32  = %AllUsersProfile%\Application Data\5c678c\AS9c5_8046.exe<br />
ProgID  = AS9c5_8046.DocHostUIHandler</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cl.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frmwrk32.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\homeav2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init32.exe \<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MalwareRemoval.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ozn695m5.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsAuxs.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsGui.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsSvc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsTray.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PC_Antispyware2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfndr.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PerAvir.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protector.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qh.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quick Heal.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\QuickHealCleaner.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Save.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveArmor.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveDefense.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveKeep.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secure Veteran.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\secureveteran.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Security Center.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SecurityFighter.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\securitysoldier.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smart.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartprotector.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smrtdefp.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftSafeness.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spywarexpguard.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrustWarrior.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\W3asbas.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windll32.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows Police Pro.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpdeluxe.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~1.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~2.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\3</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\<br />
ltTST = 7F3E0000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures = no<br />
RunInvalidSignatures = 01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\<br />
Home Security Solutions = “%AllUsersProfile%\Application Data\5c678c\AS9c5_8046.exe” /s /d</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\RunOnce\<br />
HSS = “%Temp%\scandsk211d_8046.exe” /cs:1</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Antivirus-Smart-Protection-1.png"><img class="alignnone size-medium wp-image-2808" title="Antivirus Smart Protection" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Antivirus-Smart-Protection-1-400x291.png" alt="Antivirus Smart Protection" width="400" height="291" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Antivirus-Smart-Protection-2.png"><img class="alignnone size-medium wp-image-2809" title="Antivirus Smart Protection" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Antivirus-Smart-Protection-2-400x292.png" alt="Antivirus Smart Protection" width="400" height="292" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Antivirus-Smart-Protection-3.png"><img class="alignnone size-medium wp-image-2810" title="Antivirus Smart Protection" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Antivirus-Smart-Protection-3-400x197.png" alt="Antivirus Smart Protection" width="400" height="197" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Antivirus-Smart-Protection-4.png"><img class="alignnone size-medium wp-image-2811" title="Antivirus Smart Protection" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Antivirus-Smart-Protection-4-400x303.png" alt="Antivirus Smart Protection" width="400" height="303" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Antivirus-Smart-Protection-5.png"><img class="alignnone size-medium wp-image-2812" title="Antivirus Smart Protection" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Antivirus-Smart-Protection-5-400x274.png" alt="Antivirus Smart Protection" width="400" height="274" /></a></p>
<p>To register and uninstall this rogue application, you can try one of the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>K7LY-R5GU-SI9D-EVFB</strong><strong></strong><strong>
U2FD-S2LA-H4KA-UEPB</strong></span></pre>
<p><strong>How to remove the infection of Antivirus Smart Protection </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AntivirusSmartProtection" target="_blank">Rogue.Win32.AntivirusSmartProtection</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/02/15/smart-anti-malware-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Smart Anti-Malware Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/02/21/home-malware-cleaner-rogue-removal-instructions/" rel="bookmark" class="crp_title">Home Malware Cleaner Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/03/advanced-antispyware-solution-rogue-removal-instructions/" rel="bookmark" class="crp_title">Advanced Antispyware Solution Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware Protection Center Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 14:27:18 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Protection Center]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2800</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Malware Protection Center. Emsisoft Anti-Malware detects this malware as Rogue.Win32.MalwareProtectionCenter. Malware Protection Center is a rogue scanner application, another variant of Internet Security Guard. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Malware Protection Center</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.MalwareProtectionCenter" href="http://www.emsisoft.com/en/malware/?Adware.Win32.MalwareProtectionCenter" target="_blank"><strong>Rogue.Win32.MalwareProtectionCenter</strong></a><strong>.</strong></p>
<p><strong>Malware Protection Center </strong><strong></strong>is a rogue scanner application, another variant of <a title="Rogue.Win32.InternetSecurityGuard" href="http://www.emsisoft.com/en/malware/?Adware.Win32.InternetSecurityGuard" target="_blank"><strong>Internet Security Guard</strong></a>. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\5c678c\</li>
<li>%AllUsersProfile%\Application Data\5c678c\sqlite3.dll</li>
<li>%AllUsersProfile%\Application Data\5c678c\BackUp\</li>
<li>%AllUsersProfile%\Application Data\5c678c\MPCSys\</li>
<li>%AllUsersProfile%\Application Data\5c678c\Quarantine Items\</li>
<li>%AllUsersProfile%\Application Data\5c678c\73.mof</li>
<li>%AllUsersProfile%\Application Data\5c678c\mozcrt19.dll</li>
<li>%AllUsersProfile%\Application Data\5c678c\MP5c6_8040.exe</li>
<li>%AllUsersProfile%\Application Data\5c678c\MPC.ico</li>
<li>%AllUsersProfile%\Application Data\MPJCENSJC\</li>
<li>%AllUsersProfile%\Application Data\MPJCENSJC\MPSJQIC.cfg</li>
<li>%AppData%\Malware Protection Center\</li>
<li>%AppData%\Malware Protection Center\cookies.sqlite</li>
<li>%AppData%\Malware Protection Center\Instructions.ini</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\Malware Protection Center.lnk</li>
<li>%UserProfile%\Desktop\Malware Protection Center.lnk</li>
<li>%UserProfile%\Start Menu\Malware Protection Center.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Malware Protection Center.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\Software\Classes\clsid\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\<br />
Default = Implements DocHostUIHandler<br />
LocalServer32  = %AllUsersProfile%\Application Data\5c678c\MP5c6_8040.exe<br />
ProgID  = MP5c6_8040.DocHostUIHandler</li>
<li>HKEY_LOCAL_MACHINE\Software\Classes\MP5c6_8040.DocHostUIHandler\<br />
Default  = Implements DocHostUIHandler<br />
Clsid  = {3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cl.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frmwrk32.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\homeav2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init32.exe \<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MalwareRemoval.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ozn695m5.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsAuxs.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsGui.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsSvc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsTray.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PC_Antispyware2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfndr.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PerAvir.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protector.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qh.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quick Heal.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\QuickHealCleaner.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Save.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveArmor.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveDefense.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveKeep.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secure Veteran.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\secureveteran.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Security Center.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SecurityFighter.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\securitysoldier.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smart.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartprotector.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smrtdefp.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftSafeness.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spywarexpguard.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrustWarrior.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\W3asbas.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windll32.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows Police Pro.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpdeluxe.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~1.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~2.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\3</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\<br />
ltTST = 7F3E0000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures = no<br />
RunInvalidSignatures = 01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\<br />
Malware Protection Center = “%AllUsersProfile%\Application Data\5c678c\MP5c6_8040.exe” /s /d</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\RunOnce\<br />
MPC = “%Temp%\setup.exe” /cs:1</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/MalwareProtectionCenter-1.png"><img class="alignnone size-medium wp-image-2801" title="Malware Protection Center (Rogue.Win32.MalwareProtectionCenter)" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/MalwareProtectionCenter-1-400x291.png" alt="Malware Protection Center (Rogue.Win32.MalwareProtectionCenter)" width="400" height="291" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/MalwareProtectionCenter-2.png"><img class="alignnone size-medium wp-image-2802" title="Malware Protection Center (Rogue.Win32.MalwareProtectionCenter)" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/MalwareProtectionCenter-2-400x291.png" alt="Malware Protection Center (Rogue.Win32.MalwareProtectionCenter)" width="400" height="291" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/MalwareProtectionCenter-3.png"><img class="alignnone size-medium wp-image-2803" title="Malware Protection Center (Rogue.Win32.MalwareProtectionCenter)" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/MalwareProtectionCenter-3-400x197.png" alt="Malware Protection Center (Rogue.Win32.MalwareProtectionCenter)" width="400" height="197" /></a></p>
<p>To register and uninstall this rogue application, you can try one of the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>K7LY-R5GU-SI9D-EVFB</strong> <strong>
K7LY-H4KA-SI9D-U2FD</strong> <strong>
U2FD-S2LA-H4KA-UEPB</strong></span></pre>
<p><strong>How to remove the infection of Malware Protection Center </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MalwareProtectionCenter" target="_blank">Rogue.Win32.MalwareProtectionCenter</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Smart Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/02/15/smart-anti-malware-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Smart Anti-Malware Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/02/21/home-malware-cleaner-rogue-removal-instructions/" rel="bookmark" class="crp_title">Home Malware Cleaner Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/03/advanced-antispyware-solution-rogue-removal-instructions/" rel="bookmark" class="crp_title">Advanced Antispyware Solution Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Smart Protection 2012 Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/01/23/smart-protection-2012-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/01/23/smart-protection-2012-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 23 Jan 2012 13:52:18 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Smart Protection 2012]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2796</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Smart Protection 2012. Emsisoft Anti-Malware detects this malware as Rogue.Win32.SmartProtection2012. Smart Protection 2012 is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Smart Protection 2012</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.SmartProtection2012" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartProtection2012" target="_blank"><strong>Rogue.Win32.SmartProtection2012</strong></a><strong>.</strong></p>
<p><strong>Smart Protection 2012 </strong><strong></strong>is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\</li>
<li>%AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\B7E85B320179A6C600266C1CD151FC4E</li>
<li>%AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\B7E85B320179A6C600266C1CD151FC4E.exe</li>
<li>%UserProfile%\Desktop\Smart Protection 2012.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Smart Protection 2012\</li>
<li>%UserProfile%\Start Menu\Programs\Smart Protection 2012\Smart Protection 2012.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\RunOnce\<br />
B7E85B320179A6C600266C1CD151FC4E = %AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\B7E85B320179A6C600266C1CD151FC4E.exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Uninstall\Smart Protection 2012\<br />
DisplayName = Smart Protection 2012<br />
ShortcutPath = &#8220;%AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\B7E85B320179A6C600266C1CD151FC4E.exe&#8221; Uninstall<br />
UninstallString = &#8220;%AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\B7E85B320179A6C600266C1CD151FC4E.exe&#8221; Uninstall<br />
DisplayIcon = %AllUsersProfile%\Application Data\B7E85B320179A6C600266C1CD151FC4E\B7E85B320179A6C600266C1CD151FC4E.exe,0</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/SmartProtection2012.png"><img class="alignnone size-medium wp-image-2797" title="Smart Protection 2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/SmartProtection2012-400x298.png" alt="Smart Protection 2012" width="400" height="298" /></a></p>
<p>To register this rogue application, you can use any email and try the following serial number:</p>
<pre><strong></strong><span style="color: #ff0000;"><strong>AA39754E-715219CE</strong></span></pre>
<p><strong>How to remove the infection of Smart Protection 2012 </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SmartProtection2012" target="_blank">Rogue.Win32.SmartProtection2012</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/02/29/smart-fortress-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Smart Fortress 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/smart-hdd-rogue-removal-instructions/" rel="bookmark" class="crp_title">SMART HDD Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/23/internet-security-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Smart Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/02/15/smart-anti-malware-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Smart Anti-Malware Protection Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/01/23/smart-protection-2012-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Internet Security 2012 Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/01/23/internet-security-2012-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/01/23/internet-security-2012-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 23 Jan 2012 12:56:37 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Internet Security 2012]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2790</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Internet Security 2012. Emsisoft Anti-Malware detects this malware as Rogue.Win32.InternetSecurity2012. Internet Security 2012 is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak of the <strong>Internet Security 2012</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.InternetSecurity2012" href="http://www.emsisoft.com/en/malware/?Adware.Win32.InternetSecurity2012" target="_blank"><strong>Rogue.Win32.InternetSecurity2012</strong></a><strong>.</strong></p>
<p><strong>Internet Security 2012 </strong><strong></strong>is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\isecurity.exe</li>
<li>%AllUsersProfile%\Desktop\Internet Security 2012.lnk</li>
<li>%UserProfile%\Start Menu\Internet Security 2012.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run<br />
Internet Security 2012 = %AllUsersProfile%\Desktop\Internet Security 2012.lnk</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/InternetSecurity2012.png"><img class="alignnone size-medium wp-image-2791" title="Internet Security 2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/InternetSecurity2012-400x271.png" alt="Internet Security 2012" width="400" height="271" /></a></p>
<p>To register this rogue application, you can use any email and try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong></strong><strong>Y86REW-T75FD5-U9VBF4A</strong></span></pre>
<p><strong>How to remove the infection of Internet Security 2012 </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.InternetSecurity2012" target="_blank">Rogue.Win32.InternetSecurity2012</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft Anti-Malware</a></strong>. Run a full scan on all drives and move all detected items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/10/03/security-sphere-2012-removal-instructions/" rel="bookmark" class="crp_title">Security Sphere 2012 Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/23/smart-protection-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Smart Protection 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/02/smart-hdd-rogue-removal-instructions/" rel="bookmark" class="crp_title">SMART HDD Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Security 2012 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/06/security-guard-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Guard 2012 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/01/23/internet-security-2012-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Internet Security Guard Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 16 Jan 2012 13:19:44 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Internet Security Guard]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2779</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Internet Security Guard. Emsisoft Anti-Malware detects this malware as Rogue.Win32.InternetSecurityGuard. Internet Security Guard is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Internet Security Guard</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.InternetSecurityGuard" href="http://www.emsisoft.com/en/malware/?Adware.Win32.InternetSecurityGuard" target="_blank"><strong>Rogue.Win32.InternetSecurityGuard</strong></a><strong>.</strong></p>
<p><strong>Internet Security Guard </strong><strong></strong>is                            a                                          rogue                                    application. A rogue application tries to   trick  you     by     displaying false    positive or  misleading scan   results   report,     which  says   that your    computer has a    problem, or  infected  with     viruses or  trojan,   but    you will   not be able to   fix it before    you   purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\5c678c\</li>
<li>%AllUsersProfile%\Application Data\5c678c\Quarantine Items\</li>
<li>%AllUsersProfile%\Application Data\5c678c\BackUp\</li>
<li>%AllUsersProfile%\Application Data\5c678c\ISGSys\</li>
<li>%AllUsersProfile%\Application Data\5c678c\5285.mof</li>
<li>%AllUsersProfile%\Application Data\5c678c\IS5c6_8027.exe</li>
<li>%AllUsersProfile%\Application Data\5c678c\ISG.ico</li>
<li>%AllUsersProfile%\Application Data\5c678c\mozcrt19.dll</li>
<li>%AllUsersProfile%\Application Data\5c678c\sqlite3.dll</li>
<li>%AllUsersProfile%\Application Data\ISVLVYG\</li>
<li>%AllUsersProfile%\Application Data\ISVLVYG\ISVJG.cfg</li>
<li>%AppData%\Internet Security Guard\</li>
<li>%AppData%\Internet Security Guard\Instructions.ini</li>
<li>%AppData%\Internet Security Guard\cookies.sqlite</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\Internet Security Guard.lnk</li>
<li>%UserProfile%\Desktop\Internet Security Guard.lnk</li>
<li>%UserProfile%\Start Menu\Internet Security Guard.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Internet Security Guard.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\clsid\{3F2BBC05-40DF-11D2-9455-00104BC936FF}<br />
(Default)  = Implements DocHostUIHandler<br />
LocalServer32  = %AllUsersProfile%\Application Data\5c678c\IS5c6_8027.exe<br />
ProgID  = IS5c6_8027.DocHostUIHandler</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\IS5c6_8027.DocHostUIHandler<br />
(Default)  = Implements DocHostUIHandler<br />
Clsid  = {3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cl.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frmwrk32.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\homeav2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init32.exe \<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MalwareRemoval.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ozn695m5.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsAuxs.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsGui.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsSvc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsTray.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PC_Antispyware2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfndr.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PerAvir.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protector.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qh.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quick Heal.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\QuickHealCleaner.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Save.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveArmor.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveDefense.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveKeep.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secure Veteran.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\secureveteran.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Security Center.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SecurityFighter.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\securitysoldier.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smart.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartprotector.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smrtdefp.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftSafeness.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spywarexpguard.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrustWarrior.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\W3asbas.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windll32.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows Police Pro.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpdeluxe.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~1.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~2.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\3</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\<br />
ltTST = 7F3E0000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures = no<br />
RunInvalidSignatures = 01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\<br />
Home Security Solutions = “%AllUsersProfile%\Application Data\5c678c\IS5c6_8027.exe” /s /d</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\RunOnce\<br />
HSS = “%Temp%\%malwarefile%.exe” /cs:1</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.InternetSecurityGuard_1.png"><img class="alignnone size-medium wp-image-2780" title="Rogue.Win32.InternetSecurityGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.InternetSecurityGuard_1-400x292.png" alt="Rogue.Win32.InternetSecurityGuard" width="400" height="292" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.InternetSecurityGuard_2.png"><img class="alignnone size-medium wp-image-2781" title="Rogue.Win32.InternetSecurityGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.InternetSecurityGuard_2-400x292.png" alt="Rogue.Win32.InternetSecurityGuard" width="400" height="292" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.InternetSecurityGuard_3.png"><img class="alignnone size-medium wp-image-2782" title="Rogue.Win32.InternetSecurityGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.InternetSecurityGuard_3-400x225.png" alt="Rogue.Win32.InternetSecurityGuard" width="400" height="225" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.InternetSecurityGuard_4.png"><img class="alignnone size-medium wp-image-2783" title="Rogue.Win32.InternetSecurityGuard" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.InternetSecurityGuard_4-400x303.png" alt="Rogue.Win32.InternetSecurityGuard" width="400" height="303" /></a></p>
<p>To register and uninstall this rogue application, you can try one of the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>K7LY-R5GU-SI9D-EVFB</strong>
<strong>K7LY-H4KA-SI9D-U2FD</strong>
<strong>U2FD-S2LA-H4KA-UEPB</strong></span></pre>
<p><strong>How to remove the infection of Internet Security Guard </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.InternetSecurityGuard" target="_blank">Rogue.Win32.InternetSecurityGuard</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Smart Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/02/21/home-malware-cleaner-rogue-removal-instructions/" rel="bookmark" class="crp_title">Home Malware Cleaner Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/02/15/smart-anti-malware-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Smart Anti-Malware Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/03/advanced-antispyware-solution-rogue-removal-instructions/" rel="bookmark" class="crp_title">Advanced Antispyware Solution Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>System Check Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2012/01/02/system-check-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2012/01/02/system-check-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 02 Jan 2012 06:46:47 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAlert]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[System Check]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2772</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the System Check rogue. Emsisoft Anti-Malware detects this malware as Rogue.Win32.SystemCheck. System Check is a rogue application, another variant of System Fix, System Restore, Data Restore, Data Recovery, System Recovery, Master Utilities, PC Repair, HDD Repair and System Repair. A rogue application tries to [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>System Check </strong>rogue. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.SystemCheck" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemCheck" target="_blank"><strong>Rogue.Win32.SystemCheck</strong></a><strong>.</strong></p>
<p><strong>System Check </strong>is              a                                          rogue                      application, another variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFix" target="_blank"><strong>System Fix</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRestore" target="_blank"><strong>System Restore</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataRestore"><strong>Data Restore</strong></a>, <strong><a title="Adware.Win32.DataRecovery" href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataRecovery" target="_blank">Data Recovery</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRecovery"><strong>System Recovery</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MasterUtilities"><strong>Master Utilities</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PCRepair"><strong>PC Repair</strong></a><strong>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDRepair"><strong>HDD Repair</strong></a> and <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRepair"><strong>System Repair</strong></a>.     A rogue application tries to trick you by displaying false positive   or   misleading scan results report, which says that your computer has a     problem, or infected with viruses or trojan, but you will not be  able  to   fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\[random].exe</li>
<li>%AllUsersProfile%\Application Data\[random].exe</li>
<li>%AllUsersProfile%\Application Data\~[random]</li>
<li>%AllUsersProfile%\Application Data\~[random]r</li>
<li>%AllUsersProfile%\Application Data\[random]</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\System Check.lnk</li>
<li>%UserProfile%\Desktop\System Check.lnk</li>
<li>%Temp%\3.tmp</li>
<li>%Temp%\smtmp\</li>
<li>%Temp%\smtmp\2\</li>
<li>%Temp%\smtmp\4\</li>
<li>%Temp%\smtmp\1\</li>
<li>%UserProfile%\Start Menu\Programs\System Check\</li>
<li>%UserProfile%\Start Menu\Programs\System Check\Uninstall System Check.lnk</li>
<li>%UserProfile%\Start Menu\Programs\System Check\System Check.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\policies\system\<br />
DisableTaskMgr = 01000000</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run\<br />
[random].exe = %AllUsersProfile%\Application Data\[random].exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Control Panel\<br />
nsreg = F82D014F</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Control Panel\<br />
bin =  43003A005C0044006F006&#8230;</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures = no</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Main\<br />
Use FormSuggest = Yes</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
Hidden = (empty)<br />
ShowSuperHidden = (empty)<br />
TaskbarGlomming = (empty)<br />
TaskbarGlomLevel = 02000000<br />
Start_ShowControlPanel = (empty)</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\<br />
HidNoChangingWallPaperden = 01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Policies\Associations\<br />
LowRiskFileTypess = .zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi; .mpg;.mpeg;.mov;.mp3;.m3u;.wav;.scr;</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Policies\Attachments\<br />
SaveZoneInformation = 01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\softare\Microsoft\Windows\CurrentVersion\Policies\Explorer\<br />
NoDesktop = 01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Policies\System\<br />
DisableTaskMgr = 01000000</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.SystemCheck_1.png"><img class="alignnone size-medium wp-image-2773" title="Rogue.Win32.SystemCheck" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.SystemCheck_1-400x260.png" alt="Rogue.Win32.SystemCheck" width="400" height="260" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.SystemCheck_2.png"><img class="alignnone size-medium wp-image-2774" title="Rogue.Win32.SystemCheck" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.SystemCheck_2-400x260.png" alt="Rogue.Win32.SystemCheck" width="400" height="260" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.SystemCheck_3.png"><img class="alignnone size-medium wp-image-2775" title="Rogue.Win32.SystemCheck" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.SystemCheck_3-400x260.png" alt="Rogue.Win32.SystemCheck" width="400" height="260" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.SystemCheck_4.png"><img class="alignnone size-medium wp-image-2776" title="Rogue.Win32.SystemCheck" src="http://www.anti-malware-blog.com/wp-content/uploads/2012/01/Rogue.Win32.SystemCheck_4-400x203.png" alt="Rogue.Win32.SystemCheck" width="400" height="203" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number, and enter any email:</p>
<pre><span style="color: #ff0000;"><strong>1203978628012489708290478989147</strong></span>
<strong></strong></pre>
<p><strong>How to remove the infection of System Check</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemCheck" target="_blank">Rogue.Win32.SystemCheck</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/11/15/system-fix-rogue-removal-instructions/" rel="bookmark" class="crp_title">System Fix Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/system-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">System Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/03/data-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/09/15/data-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/09/05/system-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">System Recovery Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2012/01/02/system-check-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Super AV Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/12/30/super-av-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/12/30/super-av-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 30 Dec 2011 08:30:20 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[SuperAV]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2766</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Super AV. Emsisoft Anti-Malware detects this malware as Rogue.Win32.SuperAV. Super AV is a rogue application, this is another variant of Antivirii 2011. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Super AV</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.SuperAV" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SuperAV" target="_blank"><strong>Rogue.Win32.SuperAV</strong></a><strong>.</strong></p>
<p><strong>Super AV </strong><strong></strong>is                            a                                          rogue                                    application, this is another variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.Antivirii2011" target="_blank"><strong>Antivirii 2011</strong></a>. A rogue application tries to   trick  you     by     displaying false    positive or  misleading scan   results   report,     which  says   that your    computer has a    problem, or  infected  with     viruses or  trojan,   but    you will   not be able to   fix it before    you   purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%SystemDrive%\xhergjui.exe</li>
<li>%SystemRoot%\bgmgfhpi.exe</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run\<br />
Security = %SystemRoot%\bgmgfhpi.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe\<br />
Debugger = %SystemDrive%\xhergjui.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.SuperAV_1.png"><img class="alignnone size-medium wp-image-2767" title="Rogue.Win32.SuperAV" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.SuperAV_1-400x326.png" alt="Rogue.Win32.SuperAV" width="400" height="326" /></a></p>
<p><strong>How to remove the infection of Super AV </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SuperAV" target="_blank">Rogue.Win32.SuperAV</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/12/13/antivirii-2011-rogue-removal-instructions/" rel="bookmark" class="crp_title">Antivirii 2011 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/19/security-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/07/privacy-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Privacy Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/04/13/antivirus-clean-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Clean 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/09/windows-software-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Windows Software Protection Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/12/30/super-av-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Home Security Solutions Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/12/26/home-security-solutions-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/12/26/home-security-solutions-rogue-removal-instructions/#comments</comments>
		<pubDate>Mon, 26 Dec 2011 05:27:44 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Home Security Solutions]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2757</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Home Security Solutions. Emsisoft Anti-Malware detects this malware as Rogue.Win32.HomeSecuritySolutions. Home Security Solutions is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Home Security Solutions</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.HomeSecuritySolutions" href="http://www.emsisoft.com/en/malware/?Adware.Win32.HomeSecuritySolutions" target="_blank"><strong>Rogue.Win32.HomeSecuritySolutions</strong></a><strong>.</strong></p>
<p><strong>Home Security Solutions </strong><strong></strong>is                           a                                          rogue                                   application. A rogue application tries to  trick  you     by     displaying false    positive or  misleading scan  results   report,     which  says   that your    computer has a   problem, or  infected  with     viruses or  trojan,   but    you will  not be able to   fix it before    you   purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\93d79\</li>
<li>%AllUsersProfile%\Application Data\93d79\Quarantine Items\</li>
<li>%AllUsersProfile%\Application Data\93d79\HSSSys\</li>
<li>%AllUsersProfile%\Application Data\93d79\HSS.ico</li>
<li>%AllUsersProfile%\Application Data\93d79\mozcrt19.dll</li>
<li>%AllUsersProfile%\Application Data\93d79\sqlite3.dll</li>
<li>%AllUsersProfile%\Application Data\93d79\HS147.exe</li>
<li>%AllUsersProfile%\Application Data\HSMGPBWS\</li>
<li>%AllUsersProfile%\Application Data\HSMGPBWS\HSVNAS.cfg</li>
<li>%AppData%\Home Security Solutions\</li>
<li>%AppData%\Home Security Solutions\Instructions.ini</li>
<li>%AppData%\Home Security Solutions\ScanDisk_.exe</li>
<li>%AppData%\Home Security Solutions\cookies.sqlite</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\Home Security Solutions.lnk</li>
<li>%UserProfile%\Desktop\Home Security Solutions.lnk</li>
<li>%UserProfile%\Recent\tjd.sys</li>
<li>%UserProfile%\Recent\tjd.tmp</li>
<li>%UserProfile%\Recent\CLSV.exe</li>
<li>%UserProfile%\Recent\delfile.dll</li>
<li>%UserProfile%\Recent\dudl.tmp</li>
<li>%UserProfile%\Recent\eb.sys</li>
<li>%UserProfile%\Recent\energy.sys</li>
<li>%UserProfile%\Recent\exec.exe</li>
<li>%UserProfile%\Recent\exec.tmp</li>
<li>%UserProfile%\Recent\FW.drv</li>
<li>%UserProfile%\Recent\gid.tmp</li>
<li>%UserProfile%\Recent\hymt.sys</li>
<li>%UserProfile%\Recent\kernel32.drv</li>
<li>%UserProfile%\Recent\pal.exe</li>
<li>%UserProfile%\Recent\PE.tmp</li>
<li>%UserProfile%\Recent\SICKBOY.drv</li>
<li>%UserProfile%\Recent\std.dll</li>
<li>%UserProfile%\Start Menu\Home Security Solutions.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Home Security Solutions.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\clsid\{3F2BBC05-40DF-11D2-9455-00104BC936FF}<br />
(Default)  = Implements DocHostUIHandler<br />
LocalServer32  = %AllUsersProfile%\Application Data\93d79\HS147.exe<br />
ProgID  = HS147.DocHostUIHandler</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Classes\HS147.DocHostUIHandler<br />
(Default)  = Implements DocHostUIHandler<br />
Clsid  = {3F2BBC05-40DF-11D2-9455-00104BC936FF}</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AdwarePrj.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\agent.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlphaAV.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Anti-Virus Professional.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntispywarXP2009.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPlus.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusPro_2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntivirusXP.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirusxppro2009.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiVirus_Pro.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\av360.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\brastk.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cl.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\csc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\dop.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\frmwrk32.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\gbn976rl.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\homeav2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\init32.exe \<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\MalwareRemoval.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\ozn695m5.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsAuxs.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsGui.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsSvc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pctsTray.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PC_Antispyware2010.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\pdfndr.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\PerAvir.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\personalguard.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\protector.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\qh.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quick Heal.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\QuickHealCleaner.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\rwg.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SafetyKeeper.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Save.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveArmor.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveDefense.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SaveKeep.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secure Veteran.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\secureveteran.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\Security Center.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SecurityFighter.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\securitysoldier.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smart.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartprotector.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\smrtdefp.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftSafeness.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\spywarexpguard.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tapinstall.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrustWarrior.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\tsc.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\W3asbas.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\winav.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windll32.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows Police Pro.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpdeluxe.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\xp_antispyware.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~1.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\~2.exe\<br />
Debugger = svchost.exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\3</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\<br />
ltTST = 7F3E0000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures = no<br />
RunInvalidSignatures = 01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\<br />
DisallowRun = 01000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\<br />
0 = msseces.exe<br />
1 = MSASCui.exe<br />
2 = ekrn.exe<br />
3 = egui.exe<br />
4 = avgnt.exe<br />
5 = avcenter.exe<br />
6 = avscan.exe<br />
7 = avgfrw.exe<br />
8 = avgui.exe<br />
9 = avgtray.exe<br />
10 = avgscanx.exe<br />
11 = avgcfgex.exe<br />
12 = avgemc.exe<br />
13 = avgchsvx.exe<br />
14 = avgcmgr.exe<br />
15 = avgwdsvc.exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\<br />
Home Security Solutions = &#8220;%AllUsersProfile%\Application Data\93d79\HS147.exe&#8221; /s /d</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\RunOnce\<br />
HSS = &#8220;%Temp%\scandsk211d_8016.exe&#8221; /cs:1</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.HomeSecuritySolutions_1.png"><img class="alignnone size-medium wp-image-2758" title="Rogue.Win32.HomeSecuritySolutions" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.HomeSecuritySolutions_1-400x201.png" alt="Rogue.Win32.HomeSecuritySolutions" width="400" height="201" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.HomeSecuritySolutions_2.png"><img class="alignnone size-medium wp-image-2759" title="Rogue.Win32.HomeSecuritySolutions" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.HomeSecuritySolutions_2-400x292.png" alt="Rogue.Win32.HomeSecuritySolutions" width="400" height="292" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.HomeSecuritySolutions_3.png"><img class="alignnone size-medium wp-image-2760" title="Rogue.Win32.HomeSecuritySolutions" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.HomeSecuritySolutions_3-400x292.png" alt="Rogue.Win32.HomeSecuritySolutions" width="400" height="292" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.HomeSecuritySolutions_4.png"><img class="alignnone size-medium wp-image-2761" title="Rogue.Win32.HomeSecuritySolutions" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.HomeSecuritySolutions_4-400x293.png" alt="Rogue.Win32.HomeSecuritySolutions" width="400" height="293" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.HomeSecuritySolutions_5.png"><img class="alignnone size-medium wp-image-2762" title="Rogue.Win32.HomeSecuritySolutions" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.HomeSecuritySolutions_5-400x225.png" alt="Rogue.Win32.HomeSecuritySolutions" width="400" height="225" /></a></p>
<p>To register and uninstall this rogue application, you can try one of the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>K7LY-R5GU-SI9D-EVFB</strong></span>
<span style="color: #ff0000;"><strong>K7LY-H4KA-SI9D-U2FD</strong></span>
<span style="color: #ff0000;"><strong>U2FD-S2LA-H4KA-UEPB</strong></span></pre>
<p><strong>How to remove the infection of Home Security Solutions </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HomeSecuritySolutions" target="_blank">Rogue.Win32.HomeSecuritySolutions</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/01/16/internet-security-guard-rogue-removal-instructions/" rel="bookmark" class="crp_title">Internet Security Guard Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/24/malware-protection-center-rogue-removal-instructions/" rel="bookmark" class="crp_title">Malware Protection Center Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/02/21/home-malware-cleaner-rogue-removal-instructions/" rel="bookmark" class="crp_title">Home Malware Cleaner Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/25/antivirus-smart-protection-rogue-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Smart Protection Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/04/03/advanced-antispyware-solution-rogue-removal-instructions/" rel="bookmark" class="crp_title">Advanced Antispyware Solution Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/12/26/home-security-solutions-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Monitor 2012 Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/12/14/security-monitor-2012-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/12/14/security-monitor-2012-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 14 Dec 2011 13:45:10 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Security Monitor 2012]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2748</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Security Monitor 2012. Emsisoft Anti-Malware detects this malware as Rogue.Win32.SecurityMonitor2012. Security Monitor 2012 is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Security Monitor 2012</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.SecurityMonitor2012" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecurityMonitor2012" target="_blank"><strong>Rogue.Win32.SecurityMonitor2012</strong></a><strong>.</strong></p>
<p><strong>Security Monitor 2012 </strong><strong> </strong>is                          a                                          rogue                                  application. A rogue application tries to trick  you     by     displaying false    positive or  misleading scan results   report,     which  says   that your    computer has a  problem, or  infected  with     viruses or  trojan,   but    you will not be able to   fix it before    you   purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\Security Monitor.lnk</li>
<li>%AppData%\Security Monitor\</li>
<li>%AppData%\Security Monitor\IcoHelp.ico</li>
<li>%AppData%\Security Monitor\IcoUninstall.ico</li>
<li>%AppData%\Security Monitor\Security Monitor.exe</li>
<li>%AppData%\Security Monitor\securityhelper.exe</li>
<li>%AppData%\Security Monitor\securitymanager.exe</li>
<li>%AppData%\Security Monitor\IcoActivate.ico</li>
<li>%UserProfile%\Desktop\Security Monitor.lnk</li>
<li>%Temp%\aqfitrlxi2.exe</li>
<li>%Temp%\backd-efq.exe</li>
<li>%Temp%\brdss.exe</li>
<li>%Temp%\bzqa43d.exe</li>
<li>%Temp%\cffd4.exe</li>
<li>%Temp%\cocksucker.exe</li>
<li>%Temp%\cosock.exe</li>
<li>%Temp%\cowceb.exe</li>
<li>%Temp%\cunifuc.exe</li>
<li>%Temp%\d20mes.exe</li>
<li>%Temp%\dc_3.exe</li>
<li>%Temp%\dd10x10.exe</li>
<li>%Temp%\ddoll3342.exe</li>
<li>%Temp%\destroyer.exe</li>
<li>%Temp%\dffuck.exe</li>
<li>%Temp%\dkfjd93.exe</li>
<li>%Temp%\ds7hw.exe</li>
<li>%Temp%\eelnvd13.exe</li>
<li>%Temp%\exppdf_w.exe</li>
<li>%Temp%\fadz43.exe</li>
<li>%Temp%\fe.exe</li>
<li>%Temp%\format.exe</li>
<li>%Temp%\g_dx234.exe</li>
<li>%Temp%\ggwwef9752.exe</li>
<li>%Temp%\gpupz2a.exe</li>
<li>%Temp%\hhbboll_2.exe</li>
<li>%Temp%\hiphop.exe</li>
<li>%Temp%\hodeme.exe</li>
<li>%Temp%\htfad4.exe</li>
<li>%Temp%\hvipws9.exe</li>
<li>%Temp%\jdhellwo3.exe</li>
<li>%Temp%\jkfuckfu.exe</li>
<li>%Temp%\jofcdks.exe</li>
<li>%Temp%\kjdh_gf_jjdhgd.exe</li>
<li>%Temp%\kjh102k3.exe</li>
<li>%Temp%\kn.a.exe</li>
<li>%Temp%\kock.exe</li>
<li>%Temp%\ljts-23.exe</li>
<li>%Temp%\lkhgg_ea.exe</li>
<li>%Temp%\lols.exe</li>
<li>%Temp%\ploper.exe</li>
<li>%Temp%\poertd.exe</li>
<li>%Temp%\ppddfcfux.exxe</li>
<li>%Temp%\protector2.exe</li>
<li>%Temp%\pswwg3c.exe</li>
<li>%Temp%\puzpup.exe</li>
<li>%Temp%\qwedvor.exe</li>
<li>%Temp%\qwklrvjhqlkj.exe</li>
<li>%Temp%\r0life.exe</li>
<li>%Temp%\rator.exe</li>
<li>%Temp%\rtfme.exe</li>
<li>%Temp%\safe.exe</li>
<li>%Temp%\snowif.exe</li>
<li>%Temp%\sycre.exe</li>
<li>%Temp%\timem.exe</li>
<li>%Temp%\tryh-blv.exe</li>
<li>%Temp%\w32-reno-c.exe</li>
<li>%Temp%\w32rim_mem.exe</li>
<li>%Temp%\warsddd_w.exe</li>
<li>%Temp%\wefgetn_00.exe</li>
<li>%Temp%\wined.exe</li>
<li>%Temp%\winifi.exe</li>
<li>%Temp%\wrcud12.exe</li>
<li>%Temp%\wrfwe_di.exe</li>
<li>%Temp%\wwautrsd.exe</li>
<li>%Temp%\wwwsssgen.exe</li>
<li>%Temp%\_2.tmp</li>
<li>%Temp%\1iowieoo.exe</li>
<li>%Temp%\02c9c3c35bdx5.exe</li>
<li>%Temp%\8gmsed-bd.exe</li>
<li>%Temp%\17dkf.exe</li>
<li>%Temp%\472a10e2ebxd9.exe</li>
<li>%Temp%\56493.exe</li>
<li>%Temp%\ae0965a7157cd.exe</li>
<li>%Temp%\al3erfa3.exe</li>
<li>%Temp%\alerfa.exe</li>
<li>%Temp%\alerfa2.exe</li>
<li>%Temp%\altedf.exe</li>
<li>%UserProfile%\Start Menu\Programs\Security Monitor.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Security Monitor\</li>
<li>%UserProfile%\Start Menu\Programs\Security Monitor\Help Security Monitor.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Security Monitor\How to Activate Security Monitor.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Security Monitor\Security Monitor.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Security Monitor\Activate Security Monitor.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Run\<br />
Security Monitor = &#8220;%AppData%\Security Monitor\Security Monitor.exe&#8221; /STARTUP<br />
Security Monitor 2012 Security = %AppData%\Security Monitor\securitymanager.exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows\CurrentVersion\Uninstall\Security Monitor\<br />
DisplayName = Security Monitor<br />
UninstallString = &#8220;%AppData%\Security Monitor\securityhelper.exe&#8221; /UNINSTALL<br />
DisplayIcon = &#8220;%AppData%\Security Monitor\securityhelper.exe&#8221;,1</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Security Monitor\<br />
(Default)  = %AppData%\Security Monitor<br />
BuyUrl = B65B17E3F9DA41446905D3BE0E550632B225D0DB132371E38F96D84D2B2F05B40CF125&#8230;<br />
uninstaller = %AppData%\Security Monitor\securityhelper.exe<br />
ADVid = 390<br />
InstallDir = %AppData%\Security Monitor\<br />
SoftID = Security Monitor<br />
ScanSystemOnStartup = 01000000<br />
AutomaticallyUpdates = 01000000<br />
BackgroundScan = 01000000<br />
BackgroundScanTimeout = 01000000<br />
tb = DB070C0003000E000D00090015002202<br />
InstNM =%AppData%\Security Monitor\Security Monitor.exe<br />
LastTimeStamp = FD000000<br />
LastUpdateDate = 2011/11/23</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.SecurityMonitor2012_1.png"><img class="alignnone size-medium wp-image-2749" title="Rogue.Win32.SecurityMonitor2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.SecurityMonitor2012_1-400x319.png" alt="Rogue.Win32.SecurityMonitor2012" width="400" height="319" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.SecurityMonitor2012_2.png"><img class="alignnone size-medium wp-image-2750" title="Rogue.Win32.SecurityMonitor2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.SecurityMonitor2012_2-400x315.png" alt="Rogue.Win32.SecurityMonitor2012" width="400" height="315" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.SecurityMonitor2012_3.png"><img class="alignnone size-medium wp-image-2751" title="Rogue.Win32.SecurityMonitor2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.SecurityMonitor2012_3-400x358.png" alt="Rogue.Win32.SecurityMonitor2012" width="400" height="358" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.SecurityMonitor2012_4.png"><img class="alignnone size-medium wp-image-2752" title="Rogue.Win32.SecurityMonitor2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.SecurityMonitor2012_4-400x211.png" alt="Rogue.Win32.SecurityMonitor2012" width="400" height="211" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.SecurityMonitor2012_5.png"><img class="alignnone size-medium wp-image-2753" title="Rogue.Win32.SecurityMonitor2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.SecurityMonitor2012_5-400x371.png" alt="Rogue.Win32.SecurityMonitor2012" width="400" height="371" /></a></strong></p>
<p><strong>How to remove the infection of Security Monitor 2012 </strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SecurityMonitor2012" target="_blank">Rogue.Win32.SecurityMonitor2012</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2012/02/22/antivirus-protection-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Protection 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/10/09/antivirus-studio-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">AntiVirus Studio 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">System Security 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/cloud-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Cloud Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/23/av-protection-2011-rogue-removal-instructions/" rel="bookmark" class="crp_title">AV Protection 2011 Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/12/14/security-monitor-2012-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Antivirii 2011 Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/12/13/antivirii-2011-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/12/13/antivirii-2011-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 13 Dec 2011 08:03:19 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Antivirii 2011]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2741</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Antivirii 2011. Emsisoft Anti-Malware detects this malware as Rogue.Win32.Antivirii2011. Antivirii 2011 is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Antivirii 2011</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.Antivirii2011" href="http://www.emsisoft.com/en/malware/?Adware.Win32.Antivirii2011" target="_blank"><strong>Rogue.Win32.Antivirii2011</strong></a><strong>.</strong></p>
<p><strong>Antivirii 2011 </strong><strong> </strong>is                         a                                          rogue                                 application. A rogue application tries to trick  you    by     displaying false    positive or  misleading scan results  report,     which  says   that your    computer has a  problem, or infected  with     viruses or  trojan,   but    you will not be able to  fix it before    you   purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%SystemRoot%\llwzhxdd.exe</li>
<li>%SystemRoot%\antivirii.exe</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run\<br />
Security = %SystemRoot%\llwzhxdd.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe\<br />
Debugger = C:\xhergjui.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.AntiVirii2011_1.png"><img class="alignnone size-medium wp-image-2742" title="Rogue.Win32.AntiVirii2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.AntiVirii2011_1-400x326.png" alt="Rogue.Win32.AntiVirii2011" width="400" height="326" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.AntiVirii2011_2.png"><img class="alignnone size-medium wp-image-2743" title="Rogue.Win32.AntiVirii2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.AntiVirii2011_2-376x400.png" alt="Rogue.Win32.AntiVirii2011" width="376" height="400" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.AntiVirii2011_3.png"><img class="alignnone size-medium wp-image-2744" title="Rogue.Win32.AntiVirii2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/12/Rogue.Win32.AntiVirii2011_3-400x185.png" alt="Rogue.Win32.AntiVirii2011" width="400" height="185" /></a></p>
<p><strong>How to remove the infection of Antivirii 2011 </strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.Antivirii2011" target="_blank">Rogue.Win32.Antivirii2011</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/12/30/super-av-rogue-removal-instructions/" rel="bookmark" class="crp_title">Super AV Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/19/security-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/04/13/antivirus-clean-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">Antivirus Clean 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/06/11/personal-shield-pro-adware-removal-instructions/" rel="bookmark" class="crp_title">Personal Shield Pro Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/07/24/security-shield-adware-removal-instructions-2/" rel="bookmark" class="crp_title">Security Shield Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/12/13/antivirii-2011-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>XP Antivirus 2012 (MultiFakeAV) Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/11/29/xp-antivirus-2012-multifakeav-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/11/29/xp-antivirus-2012-multifakeav-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 29 Nov 2011 13:51:44 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Fake Rean]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Win 7 Antispyware 2012]]></category>
		<category><![CDATA[Win32]]></category>
		<category><![CDATA[XP Antivirus 2012]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2735</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the XP Antivirus 2012 (MultiFakeAV). Emsisoft Anti-Malware detects this malware as Rogue.Win32.MultiFakeAV. XP Antivirus 2012 is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>XP Antivirus 2012</strong> (MultiFakeAV). <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.MultiFakeAV" href="http://www.emsisoft.com/en/malware/?Adware.Win32.MultiFakeAV" target="_blank"><strong>Rogue.Win32.MultiFakeAV</strong></a><strong>.</strong></p>
<p><strong>XP Antivirus 2012 </strong><strong></strong>is                         a                                          rogue                                 application. A rogue application tries to trick  you    by     displaying false    positive or  misleading scan results  report,     which  says   that your    computer has a  problem, or infected  with     viruses or  trojan,   but    you will not be able to  fix it before    you   purchase. This rogue scanner program able to change their name depend on the operating system, on Windows 7 for example, the name is &#8220;<strong>Win 7 Antispyware 2012</strong>&#8220;.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfile%\Application Data\157850g1p046c522p184r5dtv4q8</li>
<li>%AppData%\157850g1p046c522p184r5dtv4q8</li>
<li>%Temp%\157850g1p046c522p184r5dtv4q8</li>
<li>%UserProfile%\Templates\157850g1p046c522p184r5dtv4q8</li>
<li>%UserProfile%\Local Settings\Application Data\%random%.exe</li>
</ul>
<p><strong>Create/modify new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\<br />
command  = &#8220;%UserProfile%\Local Settings\Application Data\%random%.exe&#8221; -a &#8220;C:\Program Files\Mozilla Firefox\firefox.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\<br />
command  = &#8220;%UserProfile%\Local Settings\Application Data\%random%.exe&#8221; -a &#8220;C:\Program Files\Mozilla Firefox\firefox.exe&#8221; -safe-mode</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\software\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\<br />
command  = &#8220;%UserProfile%\Local Settings\Application Data\%random%.exe&#8221; -a &#8220;C:\Program Files\Internet Explorer\iexplore.exe&#8221;</li>
</ul>
<ul>
<li>HKEY_CLASSES_ROOT\.exe<br />
(Default) = exefile</li>
</ul>
<ul>
<li>HKEY_CLASSES_ROOT\.exe\<br />
Content Type = application/x-msdownload<br />
DefaultIcon  = %1</li>
</ul>
<ul>
<li>HKEY_CLASSES_ROOT\.exe\shell\open\command<br />
(Default) = &#8220;%UserProfile%\Local Settings\Application Data\%random%.exe&#8221; -a &#8220;%1&#8243; %*<br />
IsolatedCommand = &#8220;%1&#8243; %*</li>
</ul>
<ul>
<li>HKEY_CLASSES_ROOT\.exe\shell\runas\command<br />
(Default) = &#8220;%1&#8243; %*<br />
IsolatedCommand = &#8220;%1&#8243; %*</li>
</ul>
<ul>
<li>HKEY_CLASSES_ROOT\exefile<br />
(Default) = Application<br />
Content Type = application/x-msdownload<br />
DefaultIcon  = %1</li>
</ul>
<ul>
<li>HKEY_CLASSES_ROOT\exefile\shell\open\command<br />
(Default) = &#8220;%UserProfile%\Local Settings\Application Data\%random%.exe&#8221; -a &#8220;%1&#8243; %*<br />
IsolatedCommand = &#8220;%1&#8243; %*</li>
</ul>
<ul>
<li>HKEY_CLASSES_ROOT\exefile\shell\runas\command<br />
(Default) = &#8220;%1&#8243; %*<br />
IsolatedCommand = &#8220;%1&#8243; %*</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.MultiFakeAV_1.png"><img class="alignnone size-medium wp-image-2736" title="Rogue.Win32.MultiFakeAV" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.MultiFakeAV_1-400x281.png" alt="Rogue.Win32.MultiFakeAV" width="400" height="281" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.MultiFakeAV_6.png"><img class="alignnone size-medium wp-image-2737" title="Rogue.Win32.MultiFakeAV" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.MultiFakeAV_6-400x285.png" alt="Rogue.Win32.MultiFakeAV" width="400" height="285" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>3425-814615-3990</strong></span></pre>
<p><strong>How to remove the infection of XP Antivirus 2012 (MultiFakeAV) </strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MultiFakeAV" target="_blank">Rogue.Win32.MultiFakeAV</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/08/19/xp-home-security-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">XP Home Security 2012 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/02/22/xp-antispyware-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">XP AntiSpyware 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/11/23/win-7-antispyware-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">Win 7 Antispyware 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/02/09/xp-antivirus-pro-2010-adware-removal-instructions/" rel="bookmark" class="crp_title">XP Antivirus Pro 2010 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/02/29/smart-fortress-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Smart Fortress 2012 Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/11/29/xp-antivirus-2012-multifakeav-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cloud AV 2012 Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/11/25/cloud-av-2012-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/11/25/cloud-av-2012-rogue-removal-instructions/#comments</comments>
		<pubDate>Fri, 25 Nov 2011 06:54:00 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Cloud AV 2012]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2729</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Cloud AV 2012. Emsisoft Anti-Malware detects this malware as Rogue.Win32.CloudAV2012. Cloud AV 2011 is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Cloud AV 2012</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.CloudAV2012" href="http://www.emsisoft.com/en/malware/?Adware.Win32.CloudAV2012" target="_blank"><strong>Rogue.Win32.CloudAV2012</strong></a><strong>.</strong></p>
<p><strong>Cloud AV 2011 </strong><strong> </strong>is                        a                                          rogue                                application. A rogue application tries to trick  you    by    displaying false    positive or  misleading scan results  report,    which  says   that your    computer has a  problem, or infected  with    viruses or  trojan,   but    you will not be able to  fix it before   you   purchase.</p>
<p><strong>The following is another variant of AV Protection 2011:</strong></p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVProtection2011" target="_blank"><strong>AV Protection 2011</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVSecurity2012" target="_blank"><strong>AV Security 2012</strong></a></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemSecurity2011">System Security 2011</a></strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVProtectionOnline" target="_blank">AV Protection Online</a></strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardOnline"><strong>Guard Online</strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.CloudProtection"><strong>Cloud Protection</strong></a></li>
</ul>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\4DA54\</li>
<li>%ProgramFiles%\4DA54\lvvm.exe</li>
<li>%ProgramFiles%\LP\</li>
<li>%ProgramFiles%\LP\41F5\</li>
<li>%ProgramFiles%\LP\41F5\9.tmp</li>
<li>%ProgramFiles%\LP\41F5\18.tmp</li>
<li>%ProgramFiles%\LP\41F5\A.tmp</li>
<li>%ProgramFiles%\LP\41F5\C29.exe</li>
<li>%SystemRoot%\system32\Cloud AV 2012v121.exe</li>
<li>%AppData%\ahst.lni</li>
<li>%AppData%\dwme.exe</li>
<li>%AppData%\50C4D\</li>
<li>%AppData%\50C4D\57741.exe</li>
<li>%AppData%\50C4D\DA54.0C4</li>
<li>%AppData%\z8gTZqhYCkVlNx0\</li>
<li>%AppData%\DaQH6sWK7R9TqUe\</li>
<li>%AppData%\uS2ibF3pn5Q6W8R\</li>
<li>%AppData%\XZqjYCekIr\</li>
<li>%UserProfile%\Desktop\Cloud AV 2012.lnk</li>
<li>%Temp%\8.tmp</li>
<li>%Temp%\dwme.exe</li>
<li>%UserProfile%\Start Menu\Programs\Cloud AV 2012\</li>
<li>%UserProfile%\Start Menu\Programs\Cloud AV 2012\Cloud AV 2012.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run\<br />
fgRZ9hYXwUeOtPy8234A = %SystemRoot%\system32\Cloud AV 2012v121.exe<br />
pIBrzPNyx1v2b4m = %AppData%\dwme.exe<br />
C29.exe = %ProgramFiles%\LP\41F5\C29.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\wscsvc\<br />
Start = 0&#215;00000003</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon\<br />
Shell = explorer.exe,%AppData%\50C4D\57741.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.CloudAV2012_1.png"><img class="alignnone size-medium wp-image-2730" title="Rogue.Win32.CloudAV2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.CloudAV2012_1-400x255.png" alt="Rogue.Win32.CloudAV2012" width="400" height="255" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.CloudAV2012_2.png"><img class="alignnone size-medium wp-image-2731" title="Rogue.Win32.CloudAV2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.CloudAV2012_2-400x330.png" alt="Rogue.Win32.CloudAV2012" width="400" height="330" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.CloudAV2012_3.png"><img class="alignnone size-medium wp-image-2732" title="Rogue.Win32.CloudAV2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.CloudAV2012_3-400x248.png" alt="Rogue.Win32.CloudAV2012" width="400" height="248" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>9992665263</strong></span></pre>
<p><strong>How to remove the infection of Cloud AV 2012 </strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.CloudAV2012" target="_blank">Rogue.Win32.CloudAV2012</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/11/23/av-protection-2011-rogue-removal-instructions/" rel="bookmark" class="crp_title">AV Protection 2011 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/cloud-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Cloud Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Security 2012 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">System Security 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/19/av-protection-online-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Protection Online Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/11/25/cloud-av-2012-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AV Protection 2011 Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/11/23/av-protection-2011-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/11/23/av-protection-2011-rogue-removal-instructions/#comments</comments>
		<pubDate>Wed, 23 Nov 2011 16:48:57 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[AV Protection 2011]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2720</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the AV Protection 2011. Emsisoft Anti-Malware detects this malware as Rogue.Win32.AVProtection2011. AV Protection 2011 is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>AV Protection 2011</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.AVProtection2011" href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVProtection2011" target="_blank"><strong>Rogue.Win32.AVProtection2011</strong></a><strong>.</strong></p>
<p><strong>AV Protection 2011 </strong><strong></strong>is                       a                                          rogue                               application. A rogue application tries to trick  you   by    displaying false    positive or  misleading scan results  report,   which  says   that your    computer has a  problem, or infected  with   viruses or  trojan,   but    you will not be able to  fix it before  you   purchase.</p>
<p>The following is another variant of AV Protection 2011:</p>
<ul>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVSecurity2012" target="_blank"><strong>AV Security 2012</strong></a>,</li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemSecurity2011">System Security 2011</a>,</strong></li>
<li><strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVProtectionOnline" target="_blank">AV Protection Online</a>,</strong></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardOnline"><strong>Guard Online</strong></a>,<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.CloudProtection"><strong></strong></a></li>
<li><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.CloudProtection"><strong>Cloud Protection</strong></a>.</li>
</ul>
<p><strong>Create new files and folders:</strong></p>
<ul>
<li>%ProgramFiles%\4DA54\</li>
<li>%ProgramFiles%\4DA54\lvvm.exe</li>
<li>%ProgramFiles%\LP\</li>
<li>%ProgramFiles%\LP\41F5\</li>
<li>%ProgramFiles%\LP\41F5\17.tmp</li>
<li>%ProgramFiles%\LP\41F5\18.tmp</li>
<li>%ProgramFiles%\LP\41F5\19.tmp</li>
<li>%ProgramFiles%\LP\41F5\C29.exe</li>
<li>%SystemRoot%\system32\AV Protection 2011v121.exe</li>
<li>%AppData%\dwme.exe</li>
<li>%AppData%\ldr.ini</li>
<li>%AppData%\50C4D\</li>
<li>%AppData%\50C4D\DA54.0C4</li>
<li>%AppData%\50C4D\57741.exe</li>
<li>%AppData%\fJ6dEK8fR9YwUeO\</li>
<li>%AppData%\gkIVrlONtAuSiFp\</li>
<li>%AppData%\hP0ycS1iv3n4m6W\</li>
<li>%AppData%\XP0ucS1ib3n4Q6W\</li>
<li>%UserProfile%\Desktop\AV Protection 2011.lnk</li>
<li>%Temp%\dwme.exe</li>
<li>%Temp%\1A.tmp</li>
<li>%Temp%\16.tmp</li>
<li>%UserProfile%\Start Menu\Programs\AV Protection 2011\</li>
<li>%UserProfile%\Start Menu\Programs\AV Protection 2011\AV Protection 2011.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run\<br />
jD2onF4pm5W7E8T8234A = %SystemRoot%\system32\AV Protection 2011v121.exe<br />
AG5aQJ6dW8R9TwU = %AppData%\dwme.exe<br />
C29.exe = %ProgramFiles%\LP\41F5\C29.exe</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\wscsvc\<br />
Start = 03000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\software\Microsoft\Windows NT\CurrentVersion\Winlogon\<br />
Shell = explorer.exe,%AppData%\50C4D\57741.exe</li>
</ul>
<p>Screenshots:</p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.AVProtection2011_1.png"><img class="alignnone size-medium wp-image-2721" title="Rogue.Win32.AVProtection2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.AVProtection2011_1-400x255.png" alt="Rogue.Win32.AVProtection2011" width="400" height="255" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.AVProtection2011_2.png"><img class="alignnone size-medium wp-image-2722" title="Rogue.Win32.AVProtection2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.AVProtection2011_2-400x330.png" alt="Rogue.Win32.AVProtection2011" width="400" height="330" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.AVProtection2011_3.png"><img class="alignnone size-medium wp-image-2723" title="Rogue.Win32.AVProtection2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Rogue.Win32.AVProtection2011_3-400x248.png" alt="Rogue.Win32.AVProtection2011" width="400" height="248" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>9992665263</strong></span></pre>
<p><strong>How to remove the infection of AV Protection 2011 </strong><strong></strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVProtection2011" target="_blank">Rogue.Win32.AVProtection2011</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/11/25/cloud-av-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Cloud AV 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/19/av-protection-online-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Protection Online Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/cloud-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Cloud Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">System Security 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Security 2012 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/11/23/av-protection-2011-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>System Fix Rogue Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/11/15/system-fix-rogue-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/11/15/system-fix-rogue-removal-instructions/#comments</comments>
		<pubDate>Tue, 15 Nov 2011 09:31:34 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[System Fix]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2713</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the System Fix rogue. Emsisoft Anti-Malware detects this malware as Rogue.Win32.SystemFix. System Fix is a rogue application, another variant of System Restore, Data Restore, Data Recovery, System Recovery, Master Utilities, PC Repair, HDD Repair and System Repair. A rogue application tries to trick you [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>System Fix </strong>rogue. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Rogue.Win32.SystemFix" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFix" target="_blank"><strong>Rogue.Win32.SystemFix</strong></a><strong>.</strong></p>
<p><strong>System Fix </strong><strong> </strong>is              a                                          rogue                      application, another variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRestore" target="_blank"><strong>System Restore</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataRestore"><strong>Data Restore</strong></a>, <strong><a title="Adware.Win32.DataRecovery" href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataRecovery" target="_blank">Data Recovery</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRecovery"><strong>System Recovery</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MasterUtilities"><strong>Master Utilities</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PCRepair"><strong>PC Repair</strong></a><strong>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDRepair"><strong>HDD Repair</strong></a> and <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRepair"><strong>System Repair</strong></a>.    A rogue application tries to trick you by displaying false positive  or   misleading scan results report, which says that your computer has a    problem, or infected with viruses or trojan, but you will not be able  to   fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfiles%\Application Data\[random]</li>
<li>%AllUsersProfiles%\Application Data\[random].exe</li>
<li>%AllUsersProfiles%\Application Data\[random].exe</li>
<li>%AllUsersProfiles%\Application Data\~[random]</li>
<li>%AllUsersProfiles%\Application Data\~[random]</li>
<li>%AllUsersProfiles%\Local Settings\Temp\37dbffa0005fc824.exe</li>
<li>%AppData%\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk</li>
<li>%UserProfile%\Desktop\System Fix.lnk</li>
<li>%Temp%\36.tmp</li>
<li>%Temp%\ulN4aaevqp3o76.exe.tmp</li>
<li>%Temp%\smtmp\</li>
<li>%Temp%\smtmp\1\</li>
<li>%Temp%\smtmp\2\</li>
<li>%Temp%\smtmp\4\</li>
<li>%UserProfile%\Start Menu\Programs\System Fix\</li>
<li>%UserProfile%\Start Menu\Programs\System Fix\System Fix.lnk</li>
<li>%UserProfile%\Start Menu\Programs\System Fix\Uninstall System Fix.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Policies\Explorer\Run\<br />
[random]: %AllUsersProfiles%\Local Settings\Temp\37dbffa0005fc824.exe</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Control Panel\<br />
nsreg: 0010C24E<br />
bin: 43003A005C0044006F00630075006D006500&#8230;</li>
</ul>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\<br />
DisableTaskMgr: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\<br />
75fa38b7-8b94-4995-ad32-52e938867954:<br />
BD: 43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 74 00 73 00 20 00 61 00…</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\<br />
Use FormSuggest: “Yes”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\<br />
WarnonBadCertRecving: 0×00000000<br />
CertificateRevocation: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\<br />
NoChangingWallPaper: 0×00000001<br />
HidNoChangingWallPaperden: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\<br />
NoDesktop: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\<br />
LowRiskFileTypes:          “.zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;<br />
.mp3;.m3u;.wav;.scr;”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\<br />
SaveZoneInformation: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
%random%: “%AllUsersProfile%\Application Data\%random%.exe”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures: “no”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
Hidden: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
ShowSuperHidden: 0×00000000</li>
</ul>
<p><strong>HTTP Requests:</strong></p>
<ul>
<li>ld2repgnifnmgfk.com</li>
<li>85.121.39.27</li>
<li>galaxyadvanta.com</li>
<li>pubidviseron.com</li>
<li>subishiphil.com</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.SystemFix_1.png"><img class="alignnone size-medium wp-image-2714" title="Rogue.Win32.SystemFix" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.SystemFix_1-400x260.png" alt="Rogue.Win32.SystemFix" width="400" height="260" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.SystemFix_2.png"><img class="alignnone size-medium wp-image-2715" title="Rogue.Win32.SystemFix" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.SystemFix_2-400x260.png" alt="Rogue.Win32.SystemFix" width="400" height="260" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.SystemFix_3.png"><img class="alignnone size-medium wp-image-2716" title="Rogue.Win32.SystemFix" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.SystemFix_3-400x260.png" alt="Rogue.Win32.SystemFix" width="400" height="260" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number, and enter any email:</p>
<pre><span style="color: #ff0000;"><strong>1203978628012489708290478989147</strong></span>
<strong></strong></pre>
<p><strong>How to remove the infection of System Fix</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemFix" target="_blank">Rogue.Win32.SystemFix</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/10/03/data-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/system-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">System Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/09/15/data-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/09/05/system-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">System Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/29/pc-repair-adware-removal-instructions/" rel="bookmark" class="crp_title">PC Repair Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/11/15/system-fix-rogue-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AV Security 2012 Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/#comments</comments>
		<pubDate>Thu, 10 Nov 2011 13:05:24 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[AV Security 2012]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2708</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the AV Security 2012. Emsisoft Anti-Malware detects this malware as Adware.Win32.AVSecurity2012. AV Security 2012 is a rogue application. This is another variant of System Security 2011, AV Protection Online, Guard Online and Cloud Protection. A rogue application tries to trick you by displaying false [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>AV Security 2012</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.AVSecurity2012" href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVSecurity2012" target="_blank"><strong>Adware.Win32.AVSecurity2012</strong></a><strong>.</strong></p>
<p><strong>AV Security 2012 </strong><strong></strong>is                      a                                          rogue                              application.  This is another variant of <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemSecurity2011">System Security 2011</a>,</strong> <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVProtectionOnline" target="_blank">AV Protection Online</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardOnline"><strong>Guard Online</strong></a> and <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.CloudProtection"><strong>Cloud Protection</strong></a>.   A rogue application tries to trick  you   by    displaying false   positive or  misleading scan results  report,   which  says   that your   computer has a  problem, or infected  with   viruses or  trojan,   but   you will not be able to  fix it before  you   purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%SystemRoot%\system32\AV Security 2012v121.exe</li>
<li> %AppData%\ldr.ini</li>
<li> %AppData%\[random]\</li>
<li> %AppData%\[random]\</li>
<li> %AppData%\[random]\AV Security 2012.ico</li>
<li> %AppData%\[random]\</li>
<li> %UserProfile%\Desktop\AV Security 2012.lnk</li>
<li> %UserProfile%\Local Settings\Temp\B.tmp</li>
<li> %UserProfile%\Start Menu\Programs\AV Security 2012\</li>
<li>%UserProfile%\Start Menu\Programs\AV Security 2012\AV Security 2012.lnk</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run<br />
&#8220;[random]=%SystemRoot%\system32\AV Security 2012v121.exe&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.AVSecurity2012_1.png"><img class="alignnone size-medium wp-image-2709" title="Adware.Win32.AVSecurity2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.AVSecurity2012_1-400x255.png" alt="Adware.Win32.AVSecurity2012" width="400" height="255" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.AVSecurity2012_2.png"><img class="alignnone size-medium wp-image-2710" title="Adware.Win32.AVSecurity2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.AVSecurity2012_2-400x334.png" alt="Adware.Win32.AVSecurity2012" width="400" height="334" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.AVSecurity2012_3.png"><img class="alignnone size-medium wp-image-2711" title="Adware.Win32.AVSecurity2012" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.AVSecurity2012_3-400x251.png" alt="Adware.Win32.AVSecurity2012" width="400" height="251" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>9992665263</strong></span></pre>
<p><strong>How to remove the infection of AV Security 2012</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVSecurity2012" target="_blank">Adware.Win32.AVSecurity2012</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/11/25/cloud-av-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Cloud AV 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">System Security 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/23/av-protection-2011-rogue-removal-instructions/" rel="bookmark" class="crp_title">AV Protection 2011 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/06/security-guard-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Guard 2012 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/19/av-protection-online-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Protection Online Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Privacy Protection Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/11/07/privacy-protection-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/11/07/privacy-protection-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 07 Nov 2011 09:23:52 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Privacy Protection]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2701</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Privacy Protection. Emsisoft Anti-Malware detects this malware as Adware.Win32.PrivacyProtection. Privacy Protection is a rogue application.  A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Privacy Protection</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.PrivacyProtection" href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyProtection" target="_blank"><strong>Adware.Win32.PrivacyProtection</strong></a><strong>.</strong></p>
<p><strong>Privacy Protection </strong><strong></strong>is                      a                                          rogue                              application.   A rogue application tries to trick  you   by    displaying false   positive or  misleading scan results  report,   which  says   that your   computer has a  problem, or infected  with   viruses or  trojan,   but   you will not be able to  fix it before  you   purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li> %AllUsersProfiles%\Application Data\privacy.exe</li>
<li> %AllUsersProfiles%\Desktop\Privacy Protection.lnk</li>
<li>%Temp%\6C.tmp</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_CURRENT_USER\Software\EFF9375FC10561A906A809B93DD5038F<br />
FRun=&#8221;0&#8243;<br />
O`ld=&#8221;Qshw`bx!Qsnudbuhno&#8221;<br />
Q`ui=&#8221;B;]Enbtldour!`oe!Rduuhofr]@mm!Trdsr]@qqmhb`uhno!E&#8230;&#8221;</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER|\Software\Microsoft\Windows\CurrentVersion\Run<br />
Privacy Protection = %AllUsersProfiles%\Application Data\privacy.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.PrivacyProtection.png"><img class="alignnone size-medium wp-image-2705" title="Adware.Win32.PrivacyProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/11/Adware.Win32.PrivacyProtection-400x294.png" alt="Adware.Win32.PrivacyProtection" width="400" height="294" /></a></p>
<p><strong>How to remove the infection of Privacy Protection</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PrivacyProtection" target="_blank">Adware.Win32.PrivacyProtection</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/08/19/security-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Security Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2012/01/23/smart-protection-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Smart Protection 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/03/security-sphere-2012-removal-instructions/" rel="bookmark" class="crp_title">Security Sphere 2012 Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/06/10/protection-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Protection Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/19/av-protection-online-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Protection Online Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/11/07/privacy-protection-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>System Security 2011 Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/#comments</comments>
		<pubDate>Mon, 24 Oct 2011 02:57:03 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[System Security 2011]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2694</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the System Security 2011. Emsisoft Anti-Malware detects this malware as Adware.Win32.SystemSecurity2011. System Security 2011 is a rogue application. This is another variant of AV Protection Online, Guard Online and Cloud Protection. A rogue application tries to trick you by displaying false positive or misleading [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>System Security 2011</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.SystemSecurity2011" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemSecurity2011" target="_blank"><strong>Adware.Win32.SystemSecurity2011</strong></a><strong>.</strong></p>
<p><strong>System Security 2011 </strong><strong></strong>is                     a                                          rogue                             application.  This is another variant of <strong><a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVProtectionOnline" target="_blank">AV Protection Online</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardOnline"><strong>Guard Online</strong></a> and <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.CloudProtection"><strong>Cloud Protection</strong></a>.  A rogue application tries to trick  you   by    displaying false  positive or  misleading scan results  report,   which  says   that your  computer has a  problem, or infected  with   viruses or  trojan,   but  you will not be able to  fix it before  you   purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%SystemRoot%\system32\[random].exe</li>
<li>%AppData%\ldr.ini</li>
<li>%AppData%\svhostu.exe</li>
<li>%AppData%\[random]\</li>
<li>%AppData%\[random]\</li>
<li>%AppData%\[random]\</li>
<li>%AppData%\[random]\System Security  2011.ico</li>
<li>%AppData%\[random]\</li>
<li>%UserProfile%\Desktop\System Security  2011.lnk</li>
<li>%UserProfile%\Local Settings\Temp\B.tmp</li>
<li>%UserProfile%\Local Settings\Temp\svhostu.exe</li>
<li>%UserProfile%\Start Menu\Programs\System Security  2011\</li>
<li>%UserProfile%\Start Menu\Programs\System Security  2011\System Security  2011.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run\<br />
(String) [random] = %SystemRoot%\system32\[random].exe<br />
(String) [random] = %AppData%\svhostu.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemSecurity2011_1.png"><img class="alignnone size-medium wp-image-2695" title="Adware.Win32.SystemSecurity2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemSecurity2011_1-400x255.png" alt="Adware.Win32.SystemSecurity2011" width="400" height="255" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemSecurity2011_2.png"><img class="alignnone size-medium wp-image-2696" title="Adware.Win32.SystemSecurity2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemSecurity2011_2-400x334.png" alt="Adware.Win32.SystemSecurity2011" width="400" height="334" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemSecurity2011_3.png"><img class="alignnone size-medium wp-image-2697" title="Adware.Win32.SystemSecurity2011" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemSecurity2011_3-400x251.png" alt="Adware.Win32.SystemSecurity2011" width="400" height="251" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>9992665263</strong></span></pre>
<p><strong>How to remove the infection of System Security 2011</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemSecurity2011" target="_blank">Adware.Win32.SystemSecurity2011</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Security 2012 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/19/av-protection-online-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Protection Online Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/23/av-protection-2011-rogue-removal-instructions/" rel="bookmark" class="crp_title">AV Protection 2011 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/cloud-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Cloud Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/25/cloud-av-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Cloud AV 2012 Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AV Protection Online Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/10/19/av-protection-online-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/10/19/av-protection-online-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 19 Oct 2011 16:54:07 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[AV Protection Online]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2686</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the AV Protection Online. Emsisoft Anti-Malware detects this malware as Adware.Win32.AVProtectionOnline. AV Protection Online is a rogue application. This is another variant of Guard Online and Cloud Protection. A rogue application tries to trick you by displaying false positive or misleading scan results report, [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>AV Protection Online</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.AVProtectionOnline" href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVProtectionOnline" target="_blank"><strong>Adware.Win32.AVProtectionOnline</strong></a><strong>.</strong></p>
<p><strong>AV Protection Online </strong><strong></strong>is                    a                                          rogue                            application.  This is another variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardOnline"><strong>Guard Online</strong></a> and <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.CloudProtection"><strong>Cloud Protection</strong></a>. A rogue application tries to trick  you   by    displaying false positive or  misleading scan results  report,   which  says   that your computer has a  problem, or infected  with   viruses or  trojan,   but you will not be able to  fix it before  you   purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%SystemRoot%\system32\[random].exe</li>
<li> %AppData%\[random]\</li>
<li> %AppData%\[random]\</li>
<li> %AppData%\[random]\</li>
<li> %AppData%\[random]\</li>
<li> %AppData%\[random]\AV Protection Online.ico</li>
<li> %AppData%\ldr.ini</li>
<li> %AppData%\svhostu.exe</li>
<li> %UserProfile%\Desktop\AV Protection Online.lnk</li>
<li> %UserProfile%\Local Settings\Temp\svhostu.exe</li>
<li> %UserProfile%\Local Settings\Temp\B.tmp</li>
<li> %UserProfile%\Start Menu\Programs\AV Protection Online\</li>
<li>%UserProfile%\Start Menu\Programs\AV Protection Online\AV Protection Online.lnk</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run\<br />
(String) [random] = %SystemRoot%\system32\[random].exe<br />
(String) [random] = %UserProfile%\Local Settings\Temp\svhostu.exe</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.AVProtectionOnline_1.png"><img class="alignnone size-medium wp-image-2687" title="Adware.Win32.AVProtectionOnline" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.AVProtectionOnline_1-400x255.png" alt="Adware.Win32.AVProtectionOnline" width="400" height="255" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.AVProtectionOnline_2.png"><img class="alignnone size-medium wp-image-2688" title="Adware.Win32.AVProtectionOnline" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.AVProtectionOnline_2-400x334.png" alt="Adware.Win32.AVProtectionOnline" width="400" height="334" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.AVProtectionOnline_3.png"><img class="alignnone size-medium wp-image-2689" title="Adware.Win32.AVProtectionOnline" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.AVProtectionOnline_3-400x251.png" alt="Adware.Win32.AVProtectionOnline" width="400" height="251" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>9992665263</strong></span></pre>
<p><strong>How to remove the infection of AV Protection</strong><strong> Online </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.AVProtectionOnline" target="_blank">Adware.Win32.AVProtectionOnline</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">System Security 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Security 2012 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/guard-online-adware-removal-instructions/" rel="bookmark" class="crp_title">Guard Online Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/12/cloud-protection-adware-removal-instructions/" rel="bookmark" class="crp_title">Cloud Protection Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/23/av-protection-2011-rogue-removal-instructions/" rel="bookmark" class="crp_title">AV Protection 2011 Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/10/19/av-protection-online-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cloud Protection Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/10/12/cloud-protection-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/10/12/cloud-protection-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 12 Oct 2011 15:29:01 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[Cloud Protection]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2680</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Cloud Protection. Emsisoft Anti-Malware detects this malware as Adware.Win32.CloudProtection. Cloud Protection is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Cloud Protection</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.CloudProtection" href="http://www.emsisoft.com/en/malware/?Adware.Win32.CloudProtection" target="_blank"><strong>Adware.Win32.CloudProtection</strong></a><strong>.</strong></p>
<p><strong>Cloud Protection </strong><strong></strong><strong></strong>is                   a                                          rogue                           application.  A rogue application tries to trick you   by    displaying false positive or  misleading scan results report,   which  says   that your computer has a  problem, or infected with   viruses or  trojan,   but you will not be able to  fix it before you   purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\Internet Explorer\BE.tmp</li>
<li>%SystemRoot%\system32\%random%.exe</li>
<li>%AppData%\svhostu.exe</li>
<li>%AppData%\ldr.ini</li>
<li>%AppData%\%random%\</li>
<li>%AppData%\%random%\</li>
<li>%AppData%\%random%\</li>
<li>%AppData%\%random%\Cloud Protection.ico</li>
<li>%AppData%\%random%\</li>
<li>%UserProfile%\Desktop\Cloud Protection.lnk</li>
<li>%UserProfile%\Local Settings\Temp\BF.tmp</li>
<li>%UserProfile%\Local Settings\Temp\C1.tmp</li>
<li>%UserProfile%\Local Settings\Temp\svhostu.exe</li>
<li>%UserProfile%\Start Menu\Programs\Cloud Protection\</li>
<li>%UserProfile%\Start Menu\Programs\Cloud Protection\Cloud Protection.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Startup\crss.exe</li>
</ul>
<p><strong>Create new registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run<br />
&#8220;%random%=C:\WINDOWS\system32\%random%.exe&#8221;<br />
&#8220;%random%=%UserProfile%\Local Settings\Temp\svhostu.exe&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.CloudProtection_1.png"><img class="alignnone size-medium wp-image-2681" title="Adware.Win32.CloudProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.CloudProtection_1-400x255.png" alt="Adware.Win32.CloudProtection" width="400" height="255" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.CloudProtection_2.png"><img class="alignnone size-medium wp-image-2682" title="Adware.Win32.CloudProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.CloudProtection_2-400x334.png" alt="Adware.Win32.CloudProtection" width="400" height="334" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.CloudProtection_3.png"><img class="alignnone size-medium wp-image-2683" title="Adware.Win32.CloudProtection" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.CloudProtection_3-400x251.png" alt="Adware.Win32.CloudProtection" width="400" height="251" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>9992665263</strong></span></pre>
<p><strong>How to remove the infection of Cloud Protection</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.CloudProtection" target="_blank">Adware.Win32.CloudProtection</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/10/19/av-protection-online-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Protection Online Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">System Security 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/25/cloud-av-2012-rogue-removal-instructions/" rel="bookmark" class="crp_title">Cloud AV 2012 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/23/av-protection-2011-rogue-removal-instructions/" rel="bookmark" class="crp_title">AV Protection 2011 Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Security 2012 Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/10/12/cloud-protection-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Guard Online Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/10/12/guard-online-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/10/12/guard-online-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 12 Oct 2011 09:07:51 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Guard Online]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2676</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the Guard Online. Emsisoft Anti-Malware detects this malware as Adware.Win32.GuardOnline. Guard Online is a rogue application. A rogue application tries to trick you by displaying false positive or misleading scan results report, which says that your computer has a problem, or infected with viruses [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>Guard Online</strong>. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.GuardOnline" href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardOnline" target="_blank"><strong>Adware.Win32.GuardOnline</strong></a><strong>.</strong></p>
<p><strong>Guard Online </strong><strong></strong><strong></strong>is                  a                                          rogue                          application.  A rogue application tries to trick you  by    displaying false positive or  misleading scan results report,  which  says   that your computer has a  problem, or infected with  viruses or  trojan,   but you will not be able to  fix it before you  purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%ProgramFiles%\Internet Explorer\5C.tmp</li>
<li>%SystemRoot%\system32\%random%.exe</li>
<li>%AppData%\ldr.ini</li>
<li>%AppData%\%random%\</li>
<li>%AppData%\%random%\</li>
<li>%AppData%\%random%\Guard Online .ico</li>
<li>%AppData%\%random%\</li>
<li>%UserProfile%\Desktop\Guard Online .lnk</li>
<li>%UserProfile%\Local Settings\Temp\DX5B.tmp</li>
<li>%UserProfile%\Local Settings\Temp\DX5B.tmp.exe</li>
<li>%UserProfile%\Local Settings\Temp\5D.tmp</li>
<li>%UserProfile%\Start Menu\Programs\Guard Online\</li>
<li>%UserProfile%\Start Menu\Programs\Startup\crss.exe</li>
</ul>
<p><strong>Create new registry entry:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Run<br />
&#8220;%random%=%SystemRoot%\system32\%random%.exe&#8221;</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.GuardOnline_1.png"><img class="alignnone size-medium wp-image-2677" title="Adware.Win32.GuardOnline" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.GuardOnline_1-400x255.png" alt="Adware.Win32.GuardOnline" width="400" height="255" /></a></p>
<p><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.GuardOnline_2.png"><img class="alignnone size-medium wp-image-2678" title="Adware.Win32.GuardOnline" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.GuardOnline_2-400x334.png" alt="Adware.Win32.GuardOnline" width="400" height="334" /></a></p>
<p>To register and uninstall this rogue application, you can try the following serial number:</p>
<pre><span style="color: #ff0000;"><strong>9992665263</strong></span></pre>
<p><strong>How to remove the infection of Guard Online</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.GuardOnline" target="_blank">Adware.Win32.GuardOnline</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/10/19/av-protection-online-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Protection Online Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/24/system-security-2011-adware-removal-instructions/" rel="bookmark" class="crp_title">System Security 2011 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/10/av-security-2012-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Security 2012 Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/10/06/av-guard-online-adware-removal-instructions/" rel="bookmark" class="crp_title">AV Guard Online Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/23/av-protection-2011-rogue-removal-instructions/" rel="bookmark" class="crp_title">AV Protection 2011 Rogue Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/10/12/guard-online-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>System Restore Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2011/10/12/system-restore-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2011/10/12/system-restore-adware-removal-instructions/#comments</comments>
		<pubDate>Wed, 12 Oct 2011 08:54:26 +0000</pubDate>
		<dc:creator>emsi</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Adware]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[Malware Removal]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[System Restore]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/?p=2668</guid>
		<description><![CDATA[The Emsisoft malware research team has discovered a new outbreak of the System Restore adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.SystemRestore. System Restore is a rogue application, another variant of Data Restore, Data Recovery, System Recovery, Master Utilities, PC Repair, HDD Repair and System Repair. A rogue application tries to trick you by displaying [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>Emsisoft </strong>malware research team has discovered a new outbreak    of the <strong>System Restore </strong>adware. <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft     Anti-Malware</a></strong> detects this malware as <a title="Adware.Win32.SystemRestore" href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRestore" target="_blank"><strong>Adware.Win32.SystemRestore</strong></a><strong>.</strong></p>
<p><strong>System Restore </strong><strong></strong>is              a                                          rogue                      application, another variant of <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataRestore"><strong>Data Restore</strong></a>, <strong><a title="Adware.Win32.DataRecovery" href="http://www.emsisoft.com/en/malware/?Adware.Win32.DataRecovery" target="_blank">Data Recovery</a>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRecovery"><strong>System Recovery</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.MasterUtilities"><strong>Master Utilities</strong></a>, <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.PCRepair"><strong>PC Repair</strong></a><strong>,</strong> <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.HDDRepair"><strong>HDD Repair</strong></a> and <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRepair"><strong>System Repair</strong></a>.   A rogue application tries to trick you by displaying false positive or   misleading scan results report, which says that your computer has a   problem, or infected with viruses or trojan, but you will not be able to   fix it before you purchase.</p>
<p><strong>Create new files:</strong></p>
<ul>
<li>%AllUsersProfiles%\Application Data\~%random%r</li>
<li>%AllUsersProfiles%\Application Data\%random%.exe</li>
<li>%AllUsersProfiles%\Application Data\%random%.exe</li>
<li>%AllUsersProfiles%\Application Data\%random%</li>
<li>%AllUsersProfiles%\Application Data\~%random%</li>
<li>%UserProfile%\Desktop\System Restore.lnk</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\1\</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\2\</li>
<li>%UserProfile%\Local Settings\Temp\smtmp\4\</li>
<li>%UserProfile%\Start Menu\Programs\System Restore\</li>
<li>%UserProfile%\Start Menu\Programs\System Restore\System Restore.lnk</li>
<li>%UserProfile%\Start Menu\Programs\System Restore\Uninstall System Restore.lnk</li>
</ul>
<p><strong>Create/modify registry entries:</strong></p>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\<br />
DisableTaskMgr: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\<br />
75fa38b7-8b94-4995-ad32-52e938867954:<br />
BD: 43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 74 00 73 00 20 00 61 00…</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\<br />
Use FormSuggest: “Yes”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\<br />
WarnonBadCertRecving: 0×00000000<br />
CertificateRevocation: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\<br />
NoChangingWallPaper: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\<br />
NoDesktop: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\<br />
LowRiskFileTypes:          “.zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;<br />
.mp3;.m3u;.wav;.scr;”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\<br />
SaveZoneInformation: 0×00000001</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\<br />
%random%: “%AllUsersProfile%\Application Data\%random%.exe”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\<br />
CheckExeSignatures: “no”</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
Hidden: 0×00000000</li>
</ul>
<ul>
<li>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<br />
ShowSuperHidden: 0×00000000</li>
</ul>
<p><strong>Screenshots:</strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemRestore_1.png"><img class="alignnone size-medium wp-image-2670" title="Adware.Win32.SystemRestore" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemRestore_1-400x260.png" alt="Adware.Win32.SystemRestore" width="400" height="260" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemRestore_2.png"><img class="alignnone size-medium wp-image-2671" title="Adware.Win32.SystemRestore" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemRestore_2-400x260.png" alt="Adware.Win32.SystemRestore" width="400" height="260" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemRestore_3.png"><img class="alignnone size-medium wp-image-2672" title="Adware.Win32.SystemRestore" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemRestore_3-400x260.png" alt="Adware.Win32.SystemRestore" width="400" height="260" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemRestore_4.png"><img class="alignnone size-medium wp-image-2673" title="Adware.Win32.SystemRestore" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemRestore_4-400x229.png" alt="Adware.Win32.SystemRestore" width="400" height="229" /></a></strong></p>
<p><strong><a href="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemRestore_5.png"><img class="alignnone size-medium wp-image-2674" title="Adware.Win32.SystemRestore" src="http://www.anti-malware-blog.com/wp-content/uploads/2011/10/Adware.Win32.SystemRestore_5-400x203.png" alt="Adware.Win32.SystemRestore" width="400" height="203" /></a></strong></p>
<p>To register and uninstall this rogue application, you can try the following serial number, and enter any email:</p>
<pre><span style="color: #ff0000;"><strong>1203978628012489708290478989147</strong>
<strong></strong></span></pre>
<p><strong>How to remove the infection of System Restore</strong><strong> </strong><strong>(<a href="http://www.emsisoft.com/en/malware/?Adware.Win32.SystemRestore" target="_blank">Adware.Win32.SystemRestore</a></strong><strong>)?</strong></p>
<p>To delete this malware infection, please download and install <strong><a href="http://www.emsisoft.com/en/software/antimalware/">Emsisoft  Anti-Malware</a></strong>. Run a full scan on all drives and move all   detected           items to the quarantine.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2011/10/03/data-restore-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Restore Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/11/15/system-fix-rogue-removal-instructions/" rel="bookmark" class="crp_title">System Fix Rogue Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/09/15/data-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">Data Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/09/05/system-recovery-adware-removal-instructions/" rel="bookmark" class="crp_title">System Recovery Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2011/08/29/pc-repair-adware-removal-instructions/" rel="bookmark" class="crp_title">PC Repair Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2011/10/12/system-restore-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

